amruthpillai/reactive-resume
57.5
Adequate · 28 September 2026
84.9k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a comprehensive, self-hosted resume builder and job application tracker that enables users to create, edit, and manage professional documents alongside a Kanban-style job search workflow. It features an AI-driven agent workspace for automated resume patching and cover letter generation, supported by a robust backend handling authentication, storage, and real-time data synchronization. The platform provides multi-format export capabilities (PDF, DOCX, Markdown) and includes specialized tools like an ATS checker and public resume hosting with customizable privacy controls.
Features
AI provider configuration and prompt management
The AI package now centralizes provider definitions and prompt templates. It introduces a typed list of supported AI providers (including OpenAI, Anthropic, Gemini, Mistral, and others) with their default base URLs and display names, validated via a Zod schema. Additionally, it adds a new module for managing AI prompts, loading markdown-based templates for PDF and DOCX parsing, ATS review, and chat interactions, ensuring specific constraints like forbidding score invention in ATS reviews.
packages/ai/src · high confidence
AI provider management and testing API
The API now exposes a complete set of endpoints for managing AI provider configurations, including creating, updating, listing, and deleting saved provider/model/API key combinations. A new 'Test' endpoint allows users to validate a provider's connection and credentials server-side; successful tests automatically enable the provider, while failures provide specific error messages (e.g., invalid key, model not found, or provider outage) without exposing sensitive API keys. The system ensures that providers must be tested and enabled before they can be used for AI requests, and handles credential encryption/decryption securely.
packages/api/src/features/ai-providers · high confidence
ATS Checker now offers an optional AI writing review
Users can now run an optional AI-powered review on their resume's writing quality, in addition to the existing deterministic ATS parsing checks. This new feature is opt-in and requires the user to sign in and connect their own AI provider; the PDF file itself is never uploaded, only the extracted text. The review provides a summary, rewrite suggestions for weak bullet points, and an analysis of how well the resume aligns with a provided job description, without altering the existing ATS score.
apps/web/src/features/ats-checker · high confidence
Add Scizor resume template and icon set
The schema now includes a new resume template named "Scizor" and a comprehensive set of icons. Users can select the Scizor template for their resumes, and the new icon library is available for use within the application's UI and resume designs.
packages/schema/src · high confidence
Add guarded resume recovery comparison tooling
Introduces a new \compare-resume\ tool in the \tooling/recovery\ directory that validates and compares resume data for recovery scenarios. The implementation includes a custom JSON parser to detect duplicate keys and reject invalid inputs (such as control characters or malformed IDs) before processing, ensuring that recovery operations are blocked or handled safely based on owner verification status and source availability.
tooling/recovery · high confidence
Add per-resume setting to control public download button visibility
A new database column, show\_download\_buttons, has been added to the resume table to allow users to toggle the visibility of public download buttons on a per-resume basis. This change enables granular control over whether download options are displayed to visitors viewing a resume.
_migrations/20260905114748\_resume\_download\buttons · high confidence
Add theme and language preferences to the command palette
Users can now change the application theme (light/dark) and language directly from the command palette. A new Preferences group provides quick access to these settings, pushing dedicated sub-pages for theme selection and language switching onto the command palette stack when selected.
apps/web/src/features/command-palette/pages/preferences · high confidence
Added database reset utility
A new script at tooling/database/reset.ts has been added to allow users to completely reset the database environment. This utility drops and recreates the 'drizzle' and 'public' schemas and grants necessary permissions to the postgres user, providing a quick way to clear the database state for development or testing purposes.
tooling/database · high confidence
Added rate-limiting middleware for API endpoints
A new rate-limiting middleware has been introduced in the API package to protect specific endpoints from abuse. This middleware enforces limits on resume password requests, PDF exports, resume downloads, AI requests, storage uploads and deletions, and resume mutations. Rate limiting is active only in production environments and uses a combination of client IP, user ID, and input context to generate unique keys for each limiter.
packages/api/src/middleware · high confidence
Application tracker API with AI copilot and timeline history
The application tracker API now includes a comprehensive set of endpoints for managing job applications, including CRUD operations, bulk import, document attachment, and a detailed activity timeline that logs stage changes, notes, and scheduled interviews. A new AI copilot feature allows users to autofill application details from pasted job descriptions, score their resume fit against a job, and generate persistent cover letters or follow-up messages, with provider errors gracefully translated to BAD\_GATEWAY for better client handling.
packages/api/src/features/applications · high confidence
Automated generation of JSON Resume Schema documentation
The \tooling/semantic-css\ package now includes a new utility (\generate-reference\) that automatically builds and updates documentation for the Reactive Resume JSON schema. This tool reads the schema definition and writes structured Markdown references—specifically updating the JSON Resume Schema guide and the Skill Schema Reference—by injecting generated content into designated comment markers. It handles complex schema features like union variants and custom section types, ensuring the documentation stays synchronized with the underlying data model without manual editing.
tooling/semantic-css · high confidence
Builder UI overhaul with mobile support, version history, and AI assistant
The resume builder now features a redesigned interface that adapts to mobile devices via a tabbed layout (Edit, Preview, Design) and introduces several new capabilities directly within the builder shell. Users can now access a version history dropdown to view and restore previous resume snapshots, and an AI assistant panel that connects to an AI provider for in-resume chat and editing. The builder also includes a new dock with undo/redo, zoom controls, page layout toggling, and a copy-URL button, along with a fix that drops focus during canvas panning to prevent accidental dialog reopens.
apps/web/src/routes/builder/$resumeId/-components · high confidence
Command palette now supports deep navigation and entity search
The command palette has been enhanced with a page-based navigation system, allowing users to drill down into specific sections like Resumes, Applications, and AI Threads. Users can now search for and open existing items (such as resumes, job applications, or chat threads) directly from the palette, in addition to navigating to top-level dashboard pages. This change introduces a new \BaseCommandGroup\ component to manage the page stack and visibility, ensuring that sub-pages (like Settings or entity lists) are rendered only when active, and includes comprehensive test coverage for this new navigation behavior.
apps/web/src/features/command-palette/pages · high confidence
Dashboard route structure and cover letters entry point
The dashboard area now uses a dedicated route layout that enforces session authentication, manages sidebar state via cookies, and includes accessibility features like a 'Skip to main content' link. Visiting the dashboard root automatically redirects users to the resumes section. A new cover letters page has been added, providing a dedicated entry point that displays a header and the cover letter library component.
apps/web/src/routes/dashboard · high confidence
Database schema and data model for cover letters
The application now supports a new cover letter feature, introducing a dedicated database table to store user-specific cover letters linked to resumes and applications. This change adds the necessary database migration to create the \cover\_letter\ table with fields for content, style, and source references, alongside Zod schemas in the schema package to validate and type the cover letter data structure.
_migrations/20260905121445\_cover\_letter\library, packages/schema/src/cover-letter · high confidence
Database schema and helper utilities for AI agent workspaces
This change introduces the foundational data structures and client-side helpers required for the new AI agent workspace feature. The database migration adds five new tables—\agent\_threads\, \agent\_messages\, \agent\_actions\, \agent\_attachments\, and \ai\_providers\—along with necessary indexes and foreign key constraints to support agent-driven interactions, file attachments, and provider configuration. On the client side, a new helper module (\chat-attachments.ts\) provides utilities to convert chat attachments into the format expected by the AI SDK and to construct submission payloads that include both text and file references.
_apps/web/src/routes/agent/-helpers, migrations/20260513181752\_bent\_human\cannonball · high confidence
Database schema update for application tracking
The database schema now includes a new 'application' table to support job application tracking. This table stores details such as company, role, location, salary, status, and source, along with optional fields for resume and cover letter URLs, AI-generated metadata, match scores, and follow-up information. It is linked to the 'user' and 'resume' tables and includes indexes for efficient querying by user and update time.
_migrations/20260705191631\_polite\jocasta · high confidence
Database schema update for resume analysis storage
The database schema has been updated to support the new resume analysis feature. A new \resume\_analysis\ table has been added to store analysis results, featuring a JSONB column for the analysis data, a unique foreign key linking to the \resume\ table, and automatic timestamp tracking. An index on the \resume\_id\ column has also been created to optimize lookups.
_migrations/20260408224903\_tough\wolfsbane · high confidence
Define application tracking schema with timeline and contact details
The application tracking feature now includes a formal data schema that defines the pipeline stages (saved, applied, screening, interview, offer, rejected) with associated UI colors, along with contact information fields for email and phone. It also introduces an application timeline history capable of recording stage changes, notes, and scheduled interviews with specific details like kind, duration, and location, providing the structural foundation for the application board and calendar views.
packages/schema/src/applications · high confidence
Establishes global UI theme and accessibility styles
The application now includes a centralized \globals.css\ file that defines the core design system, including light and dark mode color palettes, typography settings (IBM Plex Sans), and border radii. This file also configures Tailwind CSS plugins for typography and animations, sets up custom easing curves for UI motion, and enforces accessibility standards by respecting \prefers-reduced-motion\ preferences and ensuring proper focus visibility for interactive elements.
packages/ui/src/styles · high confidence
Initial database schema and timezone-aware timestamp migration
The application introduces a new PostgreSQL database schema comprising tables for user accounts, API keys, passkeys, resumes, sessions, and two-factor authentication, along with the necessary foreign keys and initial indexes. A subsequent migration updates all timestamp columns across these tables to use 'timestamp with time zone' to ensure correct timezone handling and adds additional indexes on key fields like API keys, resumes, and user identifiers to improve query performance.
_migrations/20260114102228\_peaceful\_pestilence, migrations/20260115232736\_nervous\maddog · high confidence
Initial project scaffolding and configuration
The repository has been initialized with the foundational configuration files required for development and deployment. This includes a Dockerfile and Docker Compose files (compose.yml, compose.dev.yml) to orchestrate the application, database, Redis, and SeaweedFS storage. A comprehensive .env.example file documents all required environment variables for database connections, authentication, storage, and feature flags. Additionally, developer tooling is configured via biome.json for linting/formatting, commitlint.config.cjs for commit standards, and AGENTS.md/CLAUDE.md for AI assistant guidance. The project also includes a LICENSE, SECURITY.md, and DESIGN.md to establish legal, security, and design system foundations.
(repo-wide) · high confidence
Introduce Command Palette for quick navigation and actions
A new Command Palette feature has been added to the web application, accessible via the Cmd+K / Ctrl+K keyboard shortcut. This modal dialog allows users to search for and execute commands across resumes, preferences, and navigation sections. It supports a hierarchical page structure, enabling users to drill down into specific command groups and use the Backspace key to navigate back or close the palette. The implementation includes a dedicated Zustand store to manage the open state, search query, and page stack, along with comprehensive unit tests for the store's logic.
apps/web/src/features/command-palette · high confidence
Introduce Reactive Resume MCP server with resume, cover letter, and application tracking tools
The \packages/mcp/src\ directory now provides the Model Context Protocol (MCP) server implementation for Reactive Resume, exposing a comprehensive set of tools for managing resumes, cover letters, and job applications. Users can now interact with their resume data via LLMs using tools such as \list\_resumes\, \read\_resume\, \apply\_resume\_patch\, and \download\_resume\_pdf\ (which generates short-lived, authenticated download URLs). The server also supports a dedicated cover letter library with tools for creating, updating, and exporting letters, as well as a full application tracker for managing job applications, including scheduling interviews, attaching documents, and autofilling application details from job descriptions. Additionally, the server registers three structured prompts (\build\_resume\, \improve\_resume\, \review\_resume\) to guide LLMs through resume creation and refinement, and exposes resume data as MCP resources (\resume://{id}\) alongside a static JSON schema for valid patch operations.
packages/mcp/src · high confidence
Introduce dedicated cover letter library and editor
Users can now create, manage, and edit cover letters in a dedicated library separate from resumes. This feature adds a new UI for listing, searching, and importing cover letters via JSON, alongside a rich-text editor that supports name, recipient, and content fields. The editor handles optimistic updates, revision-based conflict detection (alerting users if changes were made elsewhere), and dirty-state protection to prevent accidental data loss. Cover letters can be linked to specific resumes and templates, and changes are shared between the library and the resume builder.
apps/web/src/features/cover-letters · high confidence
Introduce server-side OpenAPI specification generation and OAuth metadata endpoints
The server now includes a new \apps/server/src/openapi\ module that programmatically generates the OpenAPI specification from the application's router contracts and exposes it via the \/api/openapi\ endpoint, ensuring the published spec stays in sync with runtime behavior. This module also adds dedicated handlers for OAuth authorization server metadata and OpenID configuration, correcting the authorization server list to point to the correct internal auth path, and exposes the application build version in the health endpoint's response schema.
apps/server/src/openapi · high confidence
Introduces Semantic CSS stylesheet editor with live color editing and validation
The resume builder now includes a dedicated Semantic CSS editor that allows users to write and preview custom styles using a semantic, context-aware syntax. This new editor features a built-in color picker that preserves alpha channels and contextual values like \currentcolor\, provides intelligent autocompletion for semantic selectors and properties, and offers real-time validation with clear diagnostic messages for errors such as unsupported gradients or missing variables. A legacy banner guides users to activate their converted styles, and a focus mode helps users concentrate on their code.
apps/web/src/features/resume/stylesheet · high confidence
Introduces Semantic CSS v1 for resume styling
The stylesheet module now supports a new Semantic CSS language (v1), allowing authors to style resume components using semantic selectors (e.g., \section-heading\, \item\) and custom properties instead of generic HTML classes. This change adds a full compiler pipeline—including parsing, semantic analysis, and cascade resolution—that enforces strict limits on complexity (e.g., node count, source size) and provides detailed diagnostics for unsupported syntax or mismatched selectors. It also introduces a caching mechanism for compiled stylesheets and exposes a registry of supported properties, values, and semantic node kinds to ensure consistent, PDF-safe styling.
packages/resume/src/stylesheet · high confidence
Introduces typed contracts and validation for AI agent resume patching tools
The \packages/ai/src/tools\ directory now defines strict Zod-based schemas and TypeScript types for the agent's resume-editing capabilities. This includes contracts for asking user questions with limited choices, applying JSON Patch operations to resumes with concurrency safety via \baseUpdatedAt\ timestamps, and normalizing patch proposals. These changes ensure that resume modifications are validated at the tool boundary, preventing silent failures or conflicts when multiple edits are proposed or applied.
packages/ai/src/tools · high confidence
Local PDF text extraction for resume imports
The resume import feature now supports parsing PDF files directly in the browser without requiring an external AI provider. A new \pdf-text\ module handles the extraction by leveraging the existing ATS checker's PDF parsing logic to convert document content into plain text lines, enabling offline or privacy-preserving resume imports for users who do not wish to use cloud-based AI services.
apps/web/src/features/resume/import · high confidence
New AI agent workspace with human-in-the-loop controls and resume preview
This location introduces the core UI components for the new AI agent workspace. The AgentChat component manages the conversation flow, including a new human-in-the-loop approval system where users can approve or deny resume edits via the PatchApprovalCard, and answer clarifying questions through the AskUserQuestion component. The NewThreadSetup component provides the entry point for starting a new agent session by selecting an AI provider and a source resume. Additionally, the ResumePane component offers a side-by-side preview of the resume being edited, complete with zoom controls and PDF download functionality, while the ThreadSidebar manages the list of agent threads.
apps/web/src/routes/agent/-components · high confidence
New AI agent workspace with thread-based chat and resume integration
The application now includes a dedicated AI agent workspace accessible at the /agent route. This feature introduces a thread-based interface where users can manage conversations via a sidebar, interact with an AI chat agent, and view or edit a linked resume in a resizable panel on desktop, or switch between these views using tabs on mobile. The workspace supports creating new threads, handling read-only or archived threads, and automatically syncing resume updates across the thread list and active view.
apps/web/src/routes/agent · high confidence
New AI provider management interface in settings
The Integrations settings page now includes a dedicated AI section that allows users to add, test, and manage connections to various AI providers (such as OpenAI, Anthropic, Google Gemini, and others). This new interface features a provider picker that displays provider names in their original brand language rather than translating them, and it automatically pre-fills the base URL and model fields with sensible defaults when a provider is selected. Users can save and test their API keys directly within this section to verify connectivity.
apps/web/src/features/settings/integrations/components · high confidence
New AI-powered ATS resume review and hardened provider security
This update introduces a new ATS resume review feature that provides qualitative feedback—summary, rewrite suggestions, strengths, and job-description alignment—without returning a numeric score, and adds a robust credential management system that encrypts API keys, generates non-revealable fingerprints, and redacts secrets from API responses. It also hardens AI provider configuration by enforcing safe base-URL policies (blocking private/non-HTTPS URLs by default) and introduces capabilities detection for OpenAI web search. Under the hood, JSON generation from AI providers is made more tolerant by stripping markdown fences and extracting the outermost JSON object, and provider connection tests now offer clearer, user-facing error messages with a configurable timeout.
packages/api/src/features/ai · high confidence
New API authentication and rate-limiting infrastructure
The API package now includes core infrastructure for user authentication and request throttling. A new context module (\context.ts\) introduces \resolveUserFromRequestHeaders\, which authenticates users via API keys, Bearer tokens, or session cookies, and exposes this identity to oRPC procedures through \publicProcedure\ and \protectedProcedure\. Additionally, a new rate-limiting module (\redis.ts\) provides a \createRateLimiter\ function that attempts to use Redis for shared rate limiting but gracefully falls back to in-memory limits if Redis is unavailable. Comprehensive test coverage for both modules has been added.
packages/api/src · high confidence
New API endpoint to retrieve instance feature flags
A new public API endpoint has been added at /flags to allow clients to query the current state of instance-wide feature flags. This endpoint returns three boolean values: disableSignups (controlled by the FLAG\_DISABLE\_SIGNUPS environment variable), disableEmailAuth (controlled by FLAG\_DISABLE\_EMAIL\_AUTH), and smtpEnabled (determined by the presence of SMTP configuration variables). This enables front-end applications to adapt their behavior, such as hiding signup forms or email authentication options, based on the server's configuration.
packages/api/src/features/flags · high confidence
New Base UI-based component library with comprehensive test coverage
The \packages/ui/src/components\ directory now includes a new set of UI components (Accordion, AlertDialog, Alert, Attachment, Avatar, Badge, BrandIcon, Bubble, Button, ButtonGroup, Checkbox, and Combobox) built on top of \@base-ui/react\. These components provide a consistent, accessible interface with standardized styling and slotting via \data-slot\ attributes. Each component is accompanied by a corresponding test file (e.g., \accordion.test.tsx\, \button.test.tsx\) that verifies rendering, state management, and interaction behaviors, ensuring reliability and correctness of the new UI primitives.
packages/ui/src/components · high confidence
New DOCX export engine with layout, formatting, and safety features
The \packages/docx/src\ package introduces a new DOCX export engine that renders resumes and cover letters into Word documents. It supports A4 and Letter page formats, full-width and sidebar layouts, and template-specific header positioning (full-width, main-only, sidebar-only). The engine preserves literal whitespace (including tabs) when marked, applies whole-paragraph indentation via \data-indent\, and handles safe hyperlinking by filtering out dangerous protocols (javascript:, data:, file:, ftp:). Cover-letter-only documents are rendered without resume headers, and skill keywords can be displayed as bullet lists. The implementation includes comprehensive test coverage for document building, HTML-to-DOCX conversion, section rendering, and layout logic.
packages/docx/src · high confidence
New DeepSeek Harness plugin for Reactive Resume integration
This change introduces the \dsh-plugin-reactive-resume\ package, which connects DeepSeek Harness sessions to Reactive Resume accounts via the existing MCP server. The plugin mounts the Reactive Resume MCP tools into the Harness session using Streamable HTTP and an API key, and contributes a system-prompt section that guides the model on Reactive Resume's specific JSON Patch semantics (such as reading before writing and handling locked resumes). It is configured via a \cordis.patch.yml\ row and safely mounts nothing if no API key is provided, ensuring the profile remains bootable.
packages/dsh-plugin · high confidence
New OAuth consent and error-handling pages for authentication flows
The web application now includes dedicated UI pages for the OAuth consent flow and authentication error states. The new OAuthConsentPage allows users to explicitly review and approve or deny application access requests, displaying client details and requested scopes while handling invalid or expired requests gracefully. The AuthErrorPage provides clear, user-friendly explanations for various sign-in failures (such as cancelled sign-ins, expired tokens, or provider errors) and intelligently routes signed-in users back to their authentication settings rather than the login page. These pages are accompanied by comprehensive test coverage to ensure correct behavior across edge cases like network errors, duplicate submissions, and malformed requests.
apps/web/src/features/auth/pages · high confidence
New PDF analysis modules for resume parsing
This change introduces a suite of new TypeScript modules in \packages/resume/src/ats-pdf/analyze/\ to power the ATS PDF resume parser. The new code adds dedicated analyzers for contact details (\contact.ts\), date extraction and gap detection (\dates.ts\), section heading detection with support for side columns (\sections.ts\), and PDF operator summarization for image/text coverage (\operators.ts\). It also includes semantic analysis (\semantics.ts\) to combine these signals, text quality checks (\text-quality.ts\) to detect extraction errors, and a scoring rule catalog (\catalog.ts\) defining parseability, layout, and content checks. Comprehensive unit tests (\\*.test.ts\) are added for these new components.
packages/resume/src/ats-pdf · high confidence
New React hooks for confirmation dialogs, prompts, controlled state, and form synchronization
This change introduces four new React hooks in the web application to standardize common UI patterns. The \useConfirm\ hook provides a promise-based confirmation dialog, while \usePrompt\ offers a similar interface for collecting user text input. The \useControlledState\ hook simplifies managing controlled component state by handling the logic for both controlled and uncontrolled modes, and \useSyncFormValues\ automatically synchronizes external values to a form's state using deep equality checks. Additionally, \useFormBlocker\ leverages these primitives to prevent accidental navigation or dialog closure when a form has unsaved changes. Comprehensive test coverage has been added for all new hooks.
apps/web/src/hooks · high confidence
New UI components: Combobox, Copyright, and Donation Toast
This update introduces three new UI components to the web application. The Combobox component provides a searchable, filterable selection interface that supports single and multi-select modes, grouped options, and clear actions. The Copyright component displays the application's license (MIT), attribution to the creator, and the current app version in the footer. Additionally, a DonationToast component has been added to display a non-invasive, dismissible banner after 5 minutes, allowing users to donate via Open Collective while respecting a 30-day dismissal cookie.
apps/web/src/components/ui · high confidence
New Vercel Blob storage backend with staged upload transport
The storage feature now supports Vercel Blob as a backend alongside the existing S3 and local filesystem options. This introduces a new BlobStorageService that handles file operations using namespaced paths and private access, and adds a staged upload transport mechanism (enabled on Vercel) that allows large binary payloads to be uploaded directly to Blob before being processed by the RPC handler, improving reliability for large file uploads. The storage router and service layer have been updated to support this new backend, including image processing and content type inference.
packages/api/src/features/storage · high confidence
New account data export and deletion endpoints
The API now exposes two new authenticated endpoints under /auth: a GET /auth/account/export endpoint that returns a JSON export of the user's profile, resumes, and independent cover letters (excluding secrets like password hashes), and a DELETE /auth/account endpoint that permanently removes the user's account and associated storage files. This supports GDPR-style data portability and right-to-erasure requirements.
packages/api/src/features/auth · high confidence
New account, API key, and profile settings pages
The settings area now includes dedicated pages for managing your account, API keys, and profile. The Account page allows you to export all your data as a JSON file and permanently delete your account with a confirmation step. The API Keys page lets you create, view, and delete API keys, correctly displaying the status for keys that never expire. The Profile page enables you to update your name, username, and email address, including handling email verification changes.
apps/web/src/features/settings/pages · high confidence
New animation components: CometCard, CountUp, and Spotlight
The animation component library now includes three new UI elements. CometCard provides a 3D tilt effect that follows the mouse pointer, complete with a dynamic glare overlay and support for reduced motion preferences. CountUp renders numbers that animate from zero to a target value when scrolled into view, using spring physics and respecting accessibility settings by jumping to the final value if motion is reduced. Spotlight adds a decorative, performance-optimized background effect using CSS keyframes to create drifting radial gradients without blocking pointer events.
apps/web/src/components/animation · high confidence
New applications board with AI assistance and interview scheduling
The applications view has been rebuilt as a Kanban-style board where you can drag and drop applications between stages, with a new detail sheet that includes an AI Copilot to score your fit against job descriptions and draft cover letters or follow-up messages. You can now schedule interviews directly from the detail view and see them on a new calendar interface, while the application form supports autofill from pasted job postings and allows attaching PDF cover letters. Additionally, you can export your filtered or all applications (including archived) to CSV.
apps/web/src/features/applications · high confidence
New applications dashboard with multi-view tracking and client-side filtering
The applications page now provides a comprehensive dashboard for managing job applications, supporting four distinct views: a Kanban board, a data table, a calendar for interview scheduling, and an insights view. Users can add, import, and export applications via CSV, and apply client-side filters for tags, search terms, and archived status without triggering network refetches. The interface includes sorting options, tag-based filtering, and a command-palette-ready search experience, all grounded in the new route component and its associated test coverage.
apps/web/src/routes/dashboard/applications · high confidence
New authentication settings page with passkey and social provider management
A new Authentication Settings page has been added, allowing users to manage their password, two-factor authentication, passkeys, and connected social accounts (Google, GitHub, LinkedIn, and custom OAuth). The page includes dedicated sections for registering and deleting passkeys, enabling or disabling 2FA, and linking or unlinking social providers, with appropriate loading and error toasts for all actions.
apps/web/src/features/settings/authentication · high confidence
New builder sidebar sections and expanded export options
The resume builder's right sidebar now includes dedicated sections for ATS compatibility checks, custom styles, export, information, notes, page settings, and sharing. The ATS check section provides a live lint that runs in the browser and an optional deep check that renders the resume to PDF to verify parser readability. The export section has been redesigned to support separate downloads for resumes and cover letters, adding DOCX and Markdown formats alongside PDF and JSON. Page settings now allow free-form page formats and include clamped numeric inputs for margins to prevent crashes. Sharing settings introduce a per-resume toggle to show or hide download buttons on the public URL, along with password protection controls.
apps/web/src/routes/builder/$resumeId/-sidebar/right/sections · high confidence
New collapsible section component for the resume builder sidebar
The resume builder's right sidebar now uses a new \SectionBase\ component to render individual sections (such as Experience or Education). This component provides a consistent, collapsible accordion interface for each section, allowing users to toggle visibility and focus on specific parts of their resume. The change introduces a standardized UI pattern for section headers and content within the builder's sidebar.
apps/web/src/routes/builder/$resumeId/-sidebar/right/shared · high confidence
New context and dropdown menus for resume actions
The resume list now provides context and dropdown menus on resume cards, offering actions to Open the editor, Edit details, Duplicate, Lock/Unlock, and Delete. These menus are powered by a new \useResumeMenuActions\ hook that handles locking and deletion with confirmation dialogs and toast feedback, while duplicate and edit actions open their respective dialogs.
apps/web/src/routes/dashboard/resumes/-components/menus · high confidence
New dashboard navigation and header components
The dashboard now uses a new \DashboardHeader\ component for consistent page titles and icons, along with a \DashboardSidebar\ that provides the main navigation structure. This sidebar includes links to Resumes, Applications, Cover Letters, Agents, and ATS Checker, as well as a settings section for Profile, Preferences, Authentication, API Keys, Integrations, and Account. A command palette trigger (⌘K) is also included in the sidebar header.
apps/web/src/routes/dashboard/-components · high confidence
New deterministic ATS parseability check for resumes
The resume builder now includes a built-in ATS (Applicant Tracking System) linting engine that evaluates resume data against a catalog of 24 rules. This check validates contact information (flagging missing or malformed emails/phones), detects layout issues (such as sections missing from the page layout or prose in sidebars), and rigorously parses date periods to identify errors like unparseable formats, reversed ranges, or future-dated entries. It also enforces structural requirements, such as ensuring experience sections have visible content and standard section titles, providing users with a deterministic pass/fail report to improve resume compatibility with automated screening tools.
packages/resume/src/ats · high confidence
New dialogs for API key creation and account security settings
This change introduces new UI components for managing account security and API access. Users can now create API keys with custom names and expiration periods (1 month, 3 months, 6 months, or 1 year) via a dedicated dialog. Additionally, new dialogs allow users to change their account password and manage two-factor authentication (enable, disable, and verify TOTP setup with backup code handling). These components are registered in the application's dialog system for \api-key.create\, \auth.change-password\, \auth.two-factor.enable\, and \auth.two-factor.disable\ actions.
apps/web/src/dialogs/auth · high confidence
New font registry and fallback logic in the fonts package
The \packages/fonts/src\ module now provides a centralized font registry (\fontList\) and utility functions (\getFont\, \getWebFont\, \getPdfFallbackFontFamilies\) that manage standard PDF fonts, web fonts, and script-specific Noto fallbacks. This change introduces legacy alias resolution (e.g., mapping 'Arial' to 'Arimo') to maintain compatibility with previous versions, adds localized display names for CJK fonts, and implements logic to select appropriate fallback fonts based on locale (e.g., 'Noto Sans KR' for Korean) and script category. It also includes a \resolveBoldFontWeight\ function to ensure bold text uses the correct font face weight, and a \getWebFontSource\ function that handles missing italic variants by falling back to the normal font source.
packages/fonts/src · high confidence
New home page header and footer sections with accessibility and motion enhancements
The home page now includes dedicated Header and Footer components. The Header features a sticky navigation bar that hides on scroll down, providing access to the dashboard, theme toggle, language selection, and GitHub stars, while the Footer displays resource and community links along with social media icons for GitHub, LinkedIn, and X. Both components are built with accessibility in mind, using proper ARIA labels and semantic HTML, and the Header incorporates motion animations for smooth transitions. Comprehensive tests have been added to verify the rendering and functionality of these new sections.
_apps/web/src/routes/\home/-sections · high confidence
New import sources and improved error handling for resume data
Users can now import resumes directly from LinkedIn data exports (ZIP files containing CSVs) in addition to existing JSON and plain-text formats. The import process now provides human-readable error messages for invalid JSON or schema validation failures, replacing raw JSON dumps. Date formatting during import has been standardized to use the browser's Intl API for stable month names, and invalid month values are now explicitly handled to prevent 'undefined' rendering.
packages/import/src · high confidence
New layout editor with drag-and-drop section management and sidebar width control
The resume builder now includes a dedicated layout section that allows you to customize the resume structure. You can drag and drop sections between the main content and sidebar columns, reorder them, and move them across different pages. The sidebar width is adjustable via a slider or numeric input (10–50%). Additionally, empty sections are automatically hidden from the layout editor to keep the interface clean, and section titles in the editor intelligently reflect custom titles or fall back to default labels.
apps/web/src/routes/builder/$resumeId/-sidebar/right/sections/layout · high confidence
New layout screen components and tests
Added four new layout components—BreakpointIndicator, ErrorScreen, LoadingScreen, and NotFoundScreen—along with their corresponding test suites. The BreakpointIndicator displays the current viewport breakpoint (XS through 4XL) and supports configurable positioning. The ErrorScreen, NotFoundScreen, and LoadingScreen provide standardized user-facing views for error states, missing pages, and loading states, respectively, featuring consistent branding, accessibility labels, and navigation options.
apps/web/src/components/layout · high confidence
New left sidebar and rail navigation for the resume builder
The resume builder now features a dedicated left sidebar component that displays a scrollable list of all resume sections (such as Basics, Experience, and Custom sections) for quick navigation. A new vertical rail on the far left provides icon-based shortcuts to jump directly to any section, including a newly supported 'cover-letter' section if one exists in the resume data. Additionally, a 'LockBanner' is displayed when a resume is locked, allowing users to re-enable editing via a dedicated button.
apps/web/src/routes/builder/$resumeId/-sidebar/left · high confidence
New level display and selection components for resume sections
Added the LevelDisplay component, which renders proficiency indicators (progress bars, icons, or geometric shapes) with support for custom sizing and accessibility labels, and the LevelTypeCombobox component, which provides a dropdown to select the display style from the schema-defined options.
apps/web/src/components/level · high confidence
New locale selection combobox component
Added a new LocaleCombobox component and its supporting logic (getLocaleOptions) to allow users to select and switch the application language via a searchable dropdown. The component integrates with the existing UI Combobox, displays locale names translated into the current UI language alongside their ISO codes, and ensures searchability by keyword matching against both the translated name and the ISO code regardless of the active locale.
apps/web/src/features/locale · high confidence
New platform statistics API with in-memory caching and fallbacks
The API now exposes a new /statistics endpoint that returns total user and resume counts along with a cache timestamp, and a /statistics/github/stars endpoint for the repository's GitHub star count. These endpoints use an in-memory cache with a 6-hour TTL to reduce database and external API load, and gracefully fall back to hardcoded last-known values if the database or GitHub API is unavailable.
packages/api/src/features/statistics · high confidence
New resume list views and persistent view preferences
The Resumes dashboard now supports Grid, List, and Compact display modes, allowing users to choose the layout that best fits their workflow. View preferences are automatically saved to the browser session and restored when returning to the page, ensuring a consistent experience across sessions. The new List view provides a detailed, accessible interface with direct links to resume builders and dropdown menus for actions, while the Grid and Compact views offer visual overviews with responsive column layouts and smooth entry/exit animations.
apps/web/src/routes/dashboard/resumes/-components · high confidence
New resume template gallery with Scizor and enhanced selection UX
The resume template selection interface has been updated to include a new 'Scizor' template (single-column, uppercase headings) alongside 14 others, all now managed via a centralized metadata system. Users can browse templates in a new gallery dialog that displays static image previews, tags, and descriptions. Selecting a template now triggers a toast notification with an 'Undo' action, allowing users to revert the change immediately if desired. The gallery also highlights the currently active template with a ring indicator.
apps/web/src/dialogs/resume/template · high confidence
New right sidebar navigation for the resume builder
The resume builder now features a dedicated right sidebar that provides quick navigation to all editing sections. This new component renders a scrollable list of section-specific builders (including template, layout, typography, design, custom styles, page, notes, sharing, statistics, ATS check, export, and information) and a vertical edge menu with icons to jump directly to each section, improving workflow efficiency within the builder interface.
apps/web/src/routes/builder/$resumeId/-sidebar/right · high confidence
New shared resume logic library for cover letters, exports, and data patching
The \packages/resume/src\ directory now contains a new shared library that centralizes core resume logic previously handled elsewhere. This includes independent cover letter management (copying styles, creating isolated cover letter data, and escaping content), separate resume and cover letter export filtering, JSON Patch (RFC 6902) support for resume data updates with validation, locale-aware section item sorting by period, social media icon mapping, and OpenGraph/Twitter social meta generation. Comprehensive test coverage is added for all these new modules.
packages/resume/src · high confidence
New shared sidebar components and section options for resume building
The left sidebar now uses a new set of shared components to render and manage resume sections. \SectionBase\ provides a unified accordion wrapper for each section, enabling users to toggle section visibility, change section icons, and collapse/expand sections. \ItemsSection\ and \SectionItemList\ handle the display and drag-to-reorder of items within sections, using \motion/react\ for smooth animations. The \SectionDropdownMenu\ adds a context menu to each section, allowing users to add items, sort experience and education by date, rename sections, reset content, and toggle heading visibility. For skills sections specifically, a new \SkillKeywordLayoutMenu\ lets users switch between inline and bulleted list layouts for keywords. These changes are accompanied by tests verifying the correct behavior of the dropdown menu options and layout changes.
apps/web/src/routes/builder/$resumeId/-sidebar/left/shared · high confidence
New shared utility libraries for web app core features
This change introduces a new \apps/web/src/libs\ directory containing shared utilities that standardize core web application behaviors. It adds \error-message.ts\ to provide consistent, user-friendly error handling for oRPC and validation failures, \locale.ts\ to manage language switching and relative time formatting, \theme.ts\ to handle light/dark mode persistence, \seo.ts\ to generate structured data and social meta tags, \motion.ts\ for animation easing constants, \root-context.ts\ to aggregate initial app state, and \tanstack-form.tsx\ to provide pre-styled form field components. Comprehensive test suites are included for all new modules.
apps/web/src/libs · high confidence
New social authentication component with unified sign-in flow
A new SocialAuth component has been introduced in the web application to handle social and passkey sign-ins. This component dynamically renders buttons for Google, GitHub, LinkedIn, and custom providers based on available authentication providers, along with a dedicated Passkey option. It centralizes the sign-in logic via a runSignIn helper that manages loading states, error handling with toast notifications, and post-sign-in navigation, providing a consistent user experience for social authentication.
apps/web/src/features/auth/components · high confidence
New static assets and configuration files for branding, PWA, and SEO
This change introduces several new static files to the web application's public directory. It adds SVG assets for the favicon, app icons (light and dark modes), and the main logo (light and dark modes), along with an Open Graph logo for social sharing. A new \manifest.webmanifest\ file is added to support Progressive Web App (PWA) installation, defining app metadata, icons, and screenshots. Additionally, a \sitemap.xml\ file is included to improve search engine indexing, and the \robots.txt\ file is updated to allow crawling and reference the new sitemap. Finally, a \funding.json\ file is added to declare sponsorship and donation channels for the project.
apps/web/public · high confidence
New static server endpoints for SEO, schema, and uploads
The server now exposes dedicated static handlers for SEO metadata, JSON schema, and file uploads. The web app handler injects canonical links, Open Graph tags, and structured data (FAQ, software application) into the HTML shell for the homepage and the ATS checker page, while also serving resume-specific social metadata for public resume URLs. A new /schema.json endpoint serves the resume data JSON schema with immutable caching. The /uploads route now serves public user files with strict security headers (nosniff, noindex, same-site CORS) and blocks access to private agent attachments. Additionally, /robots.txt, /sitemap.xml, and /llms.txt are generated dynamically based on the configured app URL to improve search engine visibility and AI indexing.
apps/server/src/static · high confidence
New theme switching controls with synchronized transitions and audio feedback
The theme feature now includes a dedicated provider, toggle button, and combobox. The provider manages theme state and applies the dark/light class with a brief transition suppression to ensure all colors change simultaneously. Switching themes triggers a sound effect (switch-on or switch-off) and updates the server-side cookie. The toggle button respects the View Transitions API and prefers-reduced-motion settings, while the combobox allows users to select a theme from a list of localized options.
apps/web/src/features/theme · high confidence
New tooling infrastructure for issue triage and Docker publishing
This change introduces new tooling utilities and configuration to support issue triage and Docker publishing workflows. It adds a script (issue-labels.mjs) that automatically extracts GitHub issue labels based on specific body sections, and a test suite (docker-publishing.test.ts) that validates the logic for determining release modes (nightly, release, canary) from GitHub Actions events. Additionally, it establishes the base TypeScript and Vitest configuration for the tooling package, ensuring consistent build and test behavior.
tooling · high confidence
New typography selection components with sorted font weights
Added new UI components for selecting font families and weights in the web application. The \FontFamilyCombobox\ provides a searchable list of available fonts, while \FontWeightCombobox\ allows users to select multiple weights, automatically sorting them in ascending order. A \FontDisplay\ component renders font previews, loading web fonts on demand when they come into view. Additionally, a \getNextWeights\ utility helps identify preferred default weights (prioritizing 400 and 600) for a given font family. Tests were added to verify the sorting behavior and weight selection logic.
apps/web/src/components/typography · high confidence
New user dropdown menu component with language, theme, and sign-out options
A new \UserDropdownMenu\ component has been added to the user features area, providing a unified interface for account management. Users can now select their preferred language from a localized list, switch between light and dark themes, and sign out of their account directly from the dropdown. The component handles session validation, displays loading states during sign-out, and manages error feedback via toast notifications.
apps/web/src/features/user · high confidence
New utility modules for color, locale, file handling, and security
The \packages/utils/src\ area now includes several new modules that provide core functionality for the application. The \color\ module adds utilities to parse RGB and hex color strings, convert them to hex, and determine if a color is perceptually dark, including a fallback to \@uiw/color-convert\ for percentage-based RGB values. The \locale\ module introduces a centralized schema for supported locales using \zod\, along with helpers to detect right-to-left (RTL) scripts, CJK locales, and map locales to specific writing system scripts for PDF font selection. File handling is supported by \file.ts\, which provides functions to generate slugified filenames and trigger browser downloads via anchor elements. Security is enhanced by \url-security.node.ts\, which implements strict validation for OAuth redirect URIs by blocking private, loopback, and special-use IPv4/IPv6 addresses, ensuring that callbacks cannot be directed to internal network resources. Additionally, new modules for string manipulation (\string.ts\), CSS class merging (\style.ts\), rate limiting configuration (\rate-limit.ts\), and monorepo path resolution (\monorepo.node.ts\) have been added, all accompanied by comprehensive test suites.
packages/utils/src · high confidence
PDF templates rewritten with semantic layout and styling
The PDF templates (Azurill, Bronzor, Chikorita, Ditgar, Ditto, Gengar, and others) have been completely rewritten to use a new semantic rendering system. This change introduces semantic manifests that explicitly define layout regions (header, sidebar, main, featured) and template parts (item headers, contact rows, timeline markers), allowing for more robust and consistent layouts. The templates now support advanced features like interleaved section columns (Bronzor), featured summaries (Ditgar, Gengar), timeline visualizations (Azurill), and semantic CSS styling. Additionally, comprehensive tests have been added to verify layout alignment, pagination, and RTL support across all templates.
packages/pdf/src/templates · high confidence
Rebuilt homepage with interactive feature demos and localized language showcase
The homepage has been completely rebuilt to feature interactive, animated demonstrations of core product capabilities. Users can now explore a live ATS playground to test PDF text extraction, preview resume exports in PDF, DOCX, Markdown, and JSON formats, and interact with a feature explorer that simulates AI editing, sharing controls, and application tracking. A new language showcase section allows visitors to switch the app's display language in real-time to preview community translations. These components are supported by new shared layout utilities and CSS animations, with comprehensive test coverage added for the ATS and export playgrounds, community statistics, and the language switcher.
apps/web/src/features/homepage · high confidence
Resume editing logic and ATS validation library
This change introduces a new library at apps/web/src/libs/resume that provides the core logic for resume editing and validation. It adds deterministic ATS parseability checks (ats.ts) that scan resume data for issues like missing contact info, malformed dates, or layout problems, and provides helper functions to map those findings to specific UI locations. It also implements the item manipulation logic (move-item.ts, section-actions.ts, make-section-item.ts) used to move, create, and duplicate resume entries across standard and custom sections, ensuring stable IDs and correct layout updates. Additionally, it includes a section title resolver (section-title.ts, section-title-locale.ts) that handles localized section headings for the editor and PDF generation. The entry is accompanied by comprehensive unit tests for all these modules.
apps/web/src/libs/resume · high confidence
Support for Vercel Hobby deployment tier
The application now supports deployment on Vercel's Hobby tier alongside existing Docker deployments. This is enabled by a new API entry point (\api/index.mjs\) that re-exports the Vercel-specific server handler, and a comprehensive smoke test suite (\tooling/deployment/smoke.mjs\) that validates core functionality including health checks, authentication, resume CRUD operations, public PDF generation, and file uploads across these deployment targets.
api, tooling/deployment · high confidence
Security
Hardened OAuth callback handling and added auth layout
The authentication feature now includes a dedicated layout component for consistent styling and introduces strict validation for OAuth callback URLs to prevent open-redirect vulnerabilities. New utility functions and Zod schemas in \redirect.ts\ and \resume-password-search.ts\ sanitize callback parameters, rejecting unsafe characters, protocol-relative paths, and external origins, while ensuring that signed OAuth query parameters are correctly preserved during sign-in and passkey verification flows. Comprehensive test coverage has been added to verify these security constraints and the correct resumption of OAuth flows after authentication steps.
apps/web/src/features/auth · high confidence
Secure cover letter storage with HTML sanitization
Cover letter content and recipient details are now sanitized before being persisted to the database, stripping executable markup (such as scripts and event handlers) and unsafe CSS URL payloads while preserving rich text formatting and safe links. This change ensures that user-generated cover letter content is stored safely, preventing potential cross-site scripting (XSS) vulnerabilities in the saved documents.
packages/api/src/features/cover-letters · high confidence
Architecture
Centralized API router configuration
The API now uses a centralized router index to aggregate and expose endpoints for all major features, including AI, agents, applications, authentication, cover letters, flags, resumes, statistics, and storage. This change consolidates route definitions into a single entry point, ensuring consistent access to these services across the application.
packages/api/src/routers · high confidence
Behavioural changes
AI resume parsing now includes robust sanitization and template-based extraction
The AI resume processing pipeline in the \packages/ai/src/resume\ module has been enhanced with new \sanitize.ts\ and \extraction-template.ts\ files. The new \sanitizeAndParseResumeJson\ function now repairs malformed JSON (e.g., unquoted keys, trailing commas), coerces loose types (such as string/numeric booleans and numbers) into their correct schema types, and auto-generates IDs for items missing them. It also enforces data integrity by dropping items with missing required fields (e.g., 'company' for experience) and overriding potentially unsafe inputs for fields like \picture.url\ and \metadata.template\ with safe defaults. Additionally, the \buildAiExtractionTemplate\ function provides a structured, empty-state template for AI extraction, ensuring consistent section shapes and default values across all resume sections.
packages/ai/src/resume · high confidence
Agent API: crash-safe persistence, context pruning, and cancellation
The agent API now includes robust infrastructure for handling long-running AI interactions. Message persistence is crash-safe, using incremental drafts that fold streaming steps into a final stored message, with accumulated usage metadata to prevent token count overwrites during continuations. Context management features tiered pruning (superseding stale resume snapshots, stripping reasoning, collapsing old tool pairs, and dropping turns) to stay within token budgets, alongside a client-side merge utility for handling user questions and human-in-the-loop approvals. Additionally, a new cancellation system uses Redis to coordinate run stops across instances and monitors liveness via heartbeats, while a repair module fixes sloppy JSON from weaker models for resume patch operations.
packages/api/src/features/agent · high confidence
Agent actions schema update and workspace import enforcement
The database schema for the \agent\_actions\ table is updated to store snapshot data in a new \snapshot\_data\ JSONB column, replacing the previous \inverse\_operations\ column. Additionally, a new linting rule is enforced in the tooling layer that prevents direct imports or re-exports of source files from other workspace packages (such as \@reactive-resume\ or \apps/packages\), requiring developers to use public export maps or local feature aliases instead.
_migrations/20260519104500\_snapshot\_agent\rollbacks, tooling/grit · high confidence
Application timeline history migration
This database migration restructures the \application\ table's \activity\ JSONB column to support a detailed application timeline history. It normalizes existing activity data into structured stage and note entries, ensures every application has a valid stage entry reflecting its current status, and adds anchor timestamps to maintain accurate chronological ordering of stage transitions.
_migrations/20260708210217\_wonderful\_captain\midlands · high confidence
Auth package restructured with improved OAuth account linking and rate limiting
The auth package has been reorganized into a dedicated module with a new lazy initialization lifecycle that prevents construction during module import and handles transient failures gracefully. OAuth social login now supports implicit signup for Google, GitHub, and LinkedIn while respecting global signup restrictions, and migrated social accounts are reconciled by matching provider logins and emails to existing users. Session unlinking of providers is now allowed even for sessions older than a day by disabling the freshness gate. Rate limiting for authentication endpoints now uses Redis with a per-instance fallback when Redis is unavailable, and a new flag allows disabling API rate limits entirely. Trusted origins are automatically expanded to include localhost loopback aliases for local development.
packages/auth · high confidence
Centralized AI provider availability check
A new React hook, useHasUsableAiProvider, has been introduced to serve as the single source of truth for determining if an AI provider is ready for use. This hook checks both the enabled status and the connection test result of available providers, replacing logic that was previously duplicated across the import dialog, agent setup, and AI settings interfaces.
apps/web/src/features/settings/integrations/hooks · high confidence
Database index cleanup and optimization for user and resume tables
This migration adjusts the database schema by removing four existing indexes (user\_email\_index, user\_username\_index, resume\_statistics\_resume\_id\_index, and verification\_identifier\_index) and adding new indexes on the created\_at column for both the user and resume tables. This change optimizes query performance for time-based lookups on these core entities while removing redundant or unused index structures.
_migrations/20260210002937\_overconfident\bulldozer · high confidence
Database layer migrated to Drizzle ORM with new schema and connection handling
The database package has been restructured to use Drizzle ORM, introducing a new schema definition that supports AI agent threads and actions, job application tracking with timeline history, and a shared cover-letter library. The PostgreSQL connection logic now includes explicit error handlers on the connection pool and individual clients to prevent process crashes from dropped connections, and a shared Redis client with deployment-based key namespacing has been added. Additionally, the resume schema now defaults public download buttons to enabled, and the authentication schema has been aligned with Better Auth 1.7.3 by making the legacy 'issuer' field optional.
packages/db · high confidence
Database schema update for API key configuration
This migration modifies the 'apikey' table to support configuration-based lookups. It renames the existing 'user\_id' column to 'reference\_id' and adds a new 'config\_id' column of type text, which is non-nullable and defaults to 'default'. This structural change prepares the database for associating API keys with specific configurations rather than solely with users.
_migrations/20260305091016\_closed\pixie · high confidence
Database schema update for agent thread review patches
The database migration adds a new boolean column named \review\_patches\ to the \agent\_threads\ table. This column defaults to \false\ and is not nullable, providing the underlying storage for the new human-in-the-loop approval capability where users can review and approve agent-generated patches.
_migrations/20260820005757\_mean\_sally\floyd · high confidence
Database schema update for resume styling and rendering versioning
The database migration adds two new integer columns, \stylesheet\_revision\ and \render\_data\_version\, to the \resume\ table. These fields are initialized with a default value of 0 and are marked as NOT NULL, enabling the system to track changes in semantic CSS stylesheets and rendering data versions for user resumes.
_migrations/20260728154759\_naive\mysterio · high confidence
Database schema updated for OAuth 2.1 support
The database schema now includes new tables to support OAuth 2.1 authentication flows: \jwks\ for JSON Web Key Sets, \oauth\_access\_token\ and \oauth\_refresh\_token\ for managing token lifecycles, \oauth\_client\ for registering OAuth clients with detailed configuration options (such as redirect URIs, scopes, and PKCE requirements), and \oauth\_consent\ for tracking user authorization grants. These changes enable the backend to handle OAuth 2.1 specific features like enhanced client registration and stricter token management.
_migrations/20260323204916\_strange\_the\order · high confidence
Database schema updates for Better Auth 1.7 compatibility and JWKS support
This release includes two database migrations to support updated authentication and security features. The first migration adds an 'issuer' column to the 'account' table, backfills it with values matching Better Auth 1.7.1 (e.g., 'local:credential', 'https://accounts.google.com', 'local:oauth:\<id\>'), and enforces a unique constraint on (issuer, account\_id) to align with the new scope identity logic. The second migration adds 'alg' and 'crv' text columns to the 'jwks' table to store algorithm and curve information for JSON Web Keys.
_migrations/20260821125041\_misty\_rhino, migrations/20260824184737\_even\_roxanne\simpson · high confidence
Database schema updates for resume data migration and two-factor authentication
This release includes two database migrations. The first migration updates the 'resume' table by migrating legacy 'showLinkInTitle' settings into the 'website.inlineLink' field within the JSON data, ensuring consistent link display behavior. The second migration adds a 'verified' boolean column to the 'two\_factor' table, defaulting to true, to track the verification status of two-factor authentication records.
_migrations/20260501153733\_brave\_amazoness, migrations/20260507055641\_yellow\morg · high confidence
Database schema updates for user activity, API key defaults, and two-factor security
This update introduces two database migrations. The first adds a \last\_active\_at\ timestamp to the \user\ table and sets a default value for the \config\_id\ column in the \apikey\ table. The second migration enforces non-null constraints on the \secret\ and \backup\_codes\ columns in the \two\_factor\ table, updates default values for \rate\_limit\_time\_window\ and \rate\_limit\_max\ in the \apikey\ table, and creates new indexes on \apikey.config\_id\ and \verification.identifier\ to improve query performance.
_migrations/20260318092152\_rapid\_harpoon, migrations/20260318093141\_puzzling\pride · high confidence
Database schema updates for user roles and session impersonation
This migration introduces new columns to the database schema to support administrative and session management features. Specifically, it adds an 'impersonated\_by' column to the 'session' table to track session delegation, and adds 'role', 'banned', 'ban\_reason', and 'ban\_expires' columns to the 'user' table to enable user role assignment and account banning capabilities.
_migrations/20260401210024\_silky\_the\fallen · high confidence
Database schema updates for version history, statistics, and agent concurrency
The database schema is updated to support new product capabilities: a new \resume\_version\ table is added to store historical resume data for version history, a \resume\_statistics\_daily\ table is introduced to track daily view and download metrics per resume, and a unique partial index is added to the \agent\_threads\ table to enforce concurrency constraints on active agent threads.
_migrations/20260704092021\_wild\_goliath, migrations/20260704094544\_omniscient\_leader, migrations/20260704103440\_condemned\marvex · high confidence
Enforce unique email addresses regardless of case
A new database migration adds a unique index on the lowercased email column in the user table. This ensures that email addresses are treated as case-insensitive for uniqueness, preventing duplicate accounts that differ only by letter casing (e.g., '[e-mail redacted]' vs '[e-mail redacted]').
_migrations/20260409135213\_simple\ravenous · high confidence
Enhanced environment configuration with deployment auto-detection and stricter validation
The environment configuration in packages/env now automatically detects and normalizes settings for Vercel deployments, mapping Vercel-specific variables (like VERCEL\_URL and KV\_URL) to standard application variables (APP\_URL, REDIS\_URL) and setting appropriate storage backends. It also introduces new feature flags, including FLAG\_DISABLE\_API\_RATE\_LIMIT and FLAG\_ALLOW\_UNSAFE\_AI\_BASE\_URL, and adds validation for the ROOT\_RESUME\_ID. The server environment loader now automatically loads .env files from the workspace root while preserving existing process.env values, and rethrows non-ENOENT errors during this process.
packages/env/src · high confidence
Homepage and ATS Checker route restructuring with improved SEO and accessibility
The home route layout now conditionally renders the shared header and skip-link only on non-homepage marketing pages, allowing the main landing page to manage its own header and skip-link. The root index route now dynamically generates SEO metadata (canonical URLs, noindex tags, and structured data scripts) based on the resume's public status, and renders a public resume view or the homepage accordingly. A new ATS Checker page has been added with its own route, lazy-loaded tool component, and comprehensive social meta tags, including a fix for the missing twitter:url meta tag.
_apps/web/src/routes/\home · high confidence
Improved resume import reliability and safety
The resume import dialog now automatically detects file formats using magic bytes and JSON structure rather than relying on file extensions or MIME types, allowing it to correctly distinguish between JSON Resume, current Reactive Resume, and legacy v4 JSON exports even when metadata is missing. PDF imports no longer require an AI provider if a local browser-based parser is available, and the dialog now prevents accidental navigation away from the import screen by confirming before leaving if unsaved changes are present.
apps/web/src/dialogs/resume · high confidence
Introduce oRPC-based RPC handler and build configuration for the server app
The server application now uses a new RPC handler implementation based on the @orpc/server library, replacing previous mechanisms. This change introduces a structured RPC endpoint at /api/rpc that supports batched requests, strict GET method enforcement, and request header processing, while automatically detecting the user's locale from cookies. Additionally, the server's build process has been reconfigured to use tsdown, targeting Node.js 24 and producing ESM output, with specific bundling rules to handle Lambda compatibility and embed AI prompt assets.
apps/server · high confidence
MCP server now requires explicit authentication via OAuth or API key
The Model Context Protocol (MCP) server in the application now enforces authentication for all requests. Clients must provide either a valid OAuth Bearer token or an API key via the \x-api-key\ header to access MCP tools and resources. Unauthenticated requests will receive a 401 Unauthorized response, ensuring that only authorized users or services can interact with the resume management features exposed through the MCP interface.
apps/server/src/mcp · high confidence
Migrate authentication routes to TanStack Router
The authentication interface has been rebuilt using TanStack Router, replacing the previous routing implementation. This change introduces file-based route definitions for the entire auth flow, including login, registration, password reset, 2FA verification, and OAuth consent. The new structure enforces stricter search parameter validation via Zod schemas (e.g., for reset tokens and error codes) and centralizes session checks in \beforeLoad\ guards to redirect authenticated users or enforce re-authentication. It also adds specific handling for disabled email authentication and sign-ups, ensuring the UI correctly reflects these configuration flags.
apps/web/src/routes/auth · high confidence
Migrate web application to TanStack Router with new entry point and template preview
The web application's routing infrastructure has been replaced with TanStack Router, introducing a new entry point in main.tsx that initializes the router and cleans up server-side SEO metadata before rendering. This change includes a generated route tree defining paths for the agent workspace, cover letters, and application tracker, alongside a new settings structure where the 'danger zone' is now located under 'settings/account'. Additionally, a new template preview route at /templates/$ allows users to view resume templates as PDFs using @react-pdf/renderer, and global styles in index.css now include animations for the AI agent interface.
apps/web/src · high confidence
Migrate web authentication client to Better Auth with enhanced security plugins
The web application's authentication layer has been replaced with the Better Auth library, introducing a new client configuration in \apps/web/src/libs/auth/client.ts\. This update integrates multiple security and utility plugins, including two-factor authentication (with custom redirect logic), passkey support, API key management, admin capabilities, and OAuth provider/resource clients. A new session utility (\session.ts\) has been added to handle SPA session lookups by leveraging the new client, ensuring consistent session state retrieval across the application.
apps/web/src/libs/auth · high confidence
New API validation schemas for applications, cover letters, and resumes
The API now enforces stricter input validation and security constraints for job applications, cover letters, and resumes. Application submissions now require valid HTTP(S) source URLs, reject oversized job descriptions, and support structured contact details (email and phone) alongside PDF-only document uploads. Cover letter creation and listing now validate that resume and application context IDs are non-empty. Resume updates and imports are validated against writable data schemas to reject unsafe custom sections and invalid templates, while public resume outputs are redacted to hide owner-only fields like notes and passwords.
packages/api/src/dto · high confidence
New HTTP routing layer and security enhancements for authentication and PDF exports
The server's HTTP handling has been refactored into a new Hono-based routing layer (apps/server/src/http) that centralizes request handling. This introduces stricter security for OAuth dynamic client registration by validating redirect URIs against trusted origins and honoring client-requested token\_endpoint\_auth\_method (defaulting to 'none' for public clients). PDF exports are now separated into signed downloads (resume-pdf.ts) and public access (public-resume-pdf.ts), with the latter correctly using the transport client address for access control. The health endpoint now reports the application version and redacts sensitive internal error details from public responses.
apps/server/src/http · high confidence
New centralized dialog management system with animation-safe state handling
The application now uses a new dialog infrastructure in \apps/web/src/dialogs\ that centralizes dialog state via a Zustand store (\store.ts\) and renders content through a typed registry (\renderers.tsx\). This change introduces a specific behavioral fix: when a dialog is closed, the UI immediately hides it, but the internal state (\activeDialog\) is preserved for 300ms to allow the exit animation to complete. This prevents the dialog content from being unmounted prematurely, ensuring smooth transitions and preventing visual glitches when dialogs are opened or closed rapidly.
apps/web/src/dialogs · high confidence
New email delivery system with React-based templates
The email package now uses a new transport layer that renders React components into HTML and plain-text bodies via react-email, replacing the previous implementation. This introduces a standardized email layout (auth.tsx) used for password reset, email verification, and email change notifications, ensuring consistent styling and branding across authentication emails. The transport layer handles SMTP configuration, caching, and graceful fallbacks when SMTP is not set up, logging skipped sends instead of failing.
packages/email/src · high confidence
New resumes dashboard with local search and view preferences
The resumes list page now supports sorting by last updated, creation date, or name, and filtering by tags. A new compact view mode is available alongside the existing grid and list layouts, with the user's preferred view persisted in their session. Search functionality is performed locally on the client side, filtering resumes by name or slug without additional server requests.
apps/web/src/routes/dashboard/resumes · high confidence
New root route with SEO, motion, and donation toast integration
The application now uses a new root route component (\\_\_root.tsx\) that establishes the global layout and context providers. This change introduces a refined motion system using \motion/react\ with reduced-motion support, integrates a non-invasive donation banner (\DonationToast\) that is suppressed within the builder view, and updates SEO metadata to include Twitter card tags using \name\ attributes and a shortened meta description optimized for mobile search results.
apps/web/src/routes · high confidence
Optimized large RPC request handling with blob staging
The web client now automatically stages large RPC payloads (over 3 MB) to a temporary blob storage before sending the request, bypassing hosting ingress limits while preserving the original wire format. This optimization improves reliability for large data transfers, with a fallback to direct sending if the staging endpoint is unavailable (e.g., in Docker environments).
apps/web/src/libs/orpc · high confidence
PDF generation now uses a dedicated browser renderer with comprehensive integration tests
The PDF package now exports a \createResumePdfBlob\ function in \browser.tsx\ that renders resumes in the browser using a mocked \@react-pdf/renderer\ instance, replacing the previous server-side file generation path. This change introduces a new \RenderProvider\ context in \context.tsx\ to manage rendering options, RTL layout, and hyphenation callbacks, and updates the \ResumeDocument\ component to accept a \SectionTitleResolver\ for consistent heading generation. To ensure reliability, the diff adds extensive integration tests (\ats-extraction.integration.test.tsx\, \font-metrics.integration.test.tsx\, \glyph-cache.integration.test.tsx\, \hyphenation.integration.test.tsx\, \literal-whitespace.integration.test.tsx\, \paragraph-indent.integration.test.tsx\) that verify ATS extraction scores, font baseline alignment, CJK space preservation, German hyphenation behavior, and literal whitespace handling in the generated PDFs.
packages/pdf/src · high confidence
Persisted sidebar layout and section collapse state in the resume builder
The resume builder now remembers your workspace configuration across sessions. The sidebar panel widths (left, artboard, right) are saved to a browser cookie and restored on load, with distinct resize constraints for desktop (minimum width) and mobile (full collapse). Additionally, the collapse state of individual sidebar sections (such as Experience, Skills, or Template) is persisted in local storage, allowing users to toggle sections open or closed and have those preferences retained when they return to the builder.
apps/web/src/routes/builder/$resumeId/-store · high confidence
Public resume pages now render PDFs in-browser with configurable download controls
Public resume pages now use a client-side PDF viewer (pdfjs-dist) to render resumes directly in the browser, falling back to a server-generated PDF only if local rendering fails. The public resume view now respects a per-resume \showDownloadButtons\ preference, allowing owners to hide the 'Download PDF' buttons while keeping the document visible. Additionally, the signup link in the footer is hidden when user registration is disabled.
apps/web/src/features/resume/public · high confidence
Redesigned download dialog with Markdown export and cover letter support
The resume export interface has been redesigned to allow users to download their resume or cover letter in multiple formats, including a new Markdown option alongside PDF, DOCX, and JSON. Users can now toggle between the resume and cover letter within the download dialog, with an option to include the resume header on the cover letter. The underlying export logic has been consolidated into a single hook that handles localized section titles and supports public resume PDF generation with download statistics tracking.
apps/web/src/features/resume/export · high confidence
Removal of legacy Create React App HTML and manifest files
The default \index.html\ entry point and \manifest.json\ web app manifest provided by the initial Create React App setup have been removed. This eliminates the standard scaffolding metadata, including the default theme color, icons, and standalone display settings, indicating a shift away from the basic template structure toward a custom application configuration.
public · high confidence
Removal of resume\_analysis table
The database migration removes the \resume\_analysis\ table. This change alters the data schema by deleting the storage for resume analysis records, which may result in the loss of any data stored in this table upon migration.
_migrations/20260826151533\_flawless\_pepper\potts · high confidence
Removal of stylesheet versioning columns from the resume table
The database schema for the \resume\ table has been updated to remove the \stylesheet\_revision\ and \render\_data\_version\ columns. This change aligns with the shift to handle Semantic CSS in the browser, meaning the application no longer stores these specific versioning details in the database for resumes.
_migrations/20260816110310\_abandoned\demogoblin · high confidence
Removed Create React App default scaffolding files
The default boilerplate files generated by Create React App have been deleted from the source directory. This includes the initial application component (App.js), its associated styles (App.css), the entry point (index.js), global styles (index.css), the logo asset, the service worker registration logic, and the default test setup. Removing these files clears the slate for the application's custom implementation.
src · high confidence
Restructured dashboard settings navigation and routes
The dashboard settings interface has been reorganized into distinct, dedicated pages for Account, API Keys, Authentication, Integrations, Preferences, and Profile. Each section now has its own route (e.g., /dashboard/settings/account) with a specific header icon and title, improving navigation clarity. Additionally, the previous 'job-search' route now automatically redirects users to the new 'Integrations' settings page, consolidating related functionality.
apps/web/src/routes/dashboard/settings · high confidence
Resume API access control, validation, and export logic restructured
The resume feature's API layer has been reorganized into distinct modules for access control, CRUD operations, and exports. A new access-policy module enforces strict ownership checks for private resumes (returning NOT\_FOUND to prevent existence disclosure) and redacts owner-only fields like the dashboard title and private notes for public viewers. Input validation is now enforced at the API boundary, rejecting invalid resume data (such as malformed custom sections or out-of-range margins) before any database persistence occurs. PDF exports have been decoupled into a separate module that lazy-loads the renderer to improve server cold-start performance, supports both resume and cover-letter targets, and utilizes signed, time-limited URLs for secure downloads. Additionally, a new event system using Redis or PostgreSQL LISTEN/NOTIFY enables real-time invalidation for clients subscribing to resume updates.
packages/api/src/features/resume · high confidence
Resume builder adds password protection and hidden section recovery
Users can now protect public resume links with a password via a new dialog that enforces 6–64 character length and requires confirmation before saving. Additionally, a hidden section recovery panel in the builder sidebar lets users unhide previously hidden sections (such as Summary, Experience, or custom sections) without re-adding them, with these changes participating in undo/redo.
apps/web/src/features/resume/builder · high confidence
Resume builder route initialization and layout switching
The resume builder now initializes its state and selects the appropriate UI shell based on the device. The route loader fetches the resume data and layout preference, while the component initializes the local store and subscribes to real-time updates. It automatically switches between a desktop layout with resizable panels and a mobile layout with tabs using a single breakpoint.
apps/web/src/routes/builder/$resumeId · high confidence
Resume builder sections rewritten with TanStack Form and drag-and-drop reordering
The left sidebar sections in the resume builder have been rebuilt using TanStack Form for validation and state management, replacing the previous per-field submit approach with a single form-level listener that persists changes on every keystroke to improve responsiveness. The Basics section now includes a new Custom Fields component that lets users add, remove, and drag-and-drop reorder custom fields with icons and links. The Picture section adds a 'Fit' control (Cover vs. Contain) to control image scaling, and preserves the original file when cropping is skipped or cancelled. The Custom section builder now supports toggling section visibility and reordering items. All section builders (Education, Experience, Awards, Certifications, Interests, Languages, Publications, References, Volunteer, Profiles, Projects, Skills, Summary) now use a shared ItemsSection pattern with consistent title/subtitle mapping and 'Add a new X' affordances, and are covered by new tests verifying field labels, subtitle logic, and UI behavior.
apps/web/src/routes/builder/$resumeId/-sidebar/left/sections · high confidence
Resume cards now use cached, high-resolution thumbnails
The resume list cards now display sharp, device-pixel-ratio-aware thumbnails that are generated from the resume PDF and cached in React Query. This ensures that thumbnails remain visible and high-quality during window resizes or when the card is re-mounted, while also cleaning up memory by revoking unused image URLs.
apps/web/src/routes/dashboard/resumes/-components/cards · high confidence
Resume data schema validation and default configuration
The resume data schema now enforces stricter validation for submitted data, rejecting invalid write values and renderer-unsafe custom sections before PDF or DOCX dispatch. Legacy resume data is automatically migrated to ensure backward compatibility, including defaulting heading visibility to true for older summary and section data. A new default resume configuration has been introduced, establishing the 'onyx' template as the standard starting point with A4 page format, en-US locale, and specific typography settings. Additionally, the schema now supports semantic CSS stylesheets, allowing users to apply custom styling via a dedicated mode and source structure.
packages/schema/src/resume · high confidence
Resume preview now renders PDFs via canvas with improved thumbnail fidelity
The resume preview in the web app now uses a client-side PDF.js canvas renderer to display resume pages, replacing the previous method. This change ensures thumbnails and preview pages are rendered at the correct pixel density for the user's display, fixing issues with blurry or misaligned content (especially in RTL layouts). The preview now supports smooth layer transitions when switching templates, maintains the last valid preview during generation errors, and includes a new accessible text component that exposes structured, semantic content for screen readers while safely sanitizing HTML.
apps/web/src/features/resume/preview · high confidence
Resume section dialogs rewritten with TanStack Form and unified shell
The resume builder's section dialogs (awards, certifications, cover letter, custom, education, experience, interests, languages, profiles, projects, publications, and more) have been rewritten to use the TanStack Form library and a shared SectionItemDialog shell. This standardizes the create and update flows across all sections, ensuring consistent form validation, submission handling, and UI behavior. The experience section now supports role progression with drag-and-drop reordering, and the cover letter dialog includes an import-from-library feature. Custom sections can now be created and updated with type selection, icon picking, and layout options.
apps/web/src/dialogs/resume/sections · high confidence
SEO metadata and password protection for public resume pages
Public resume pages now include structured social card metadata (Open Graph tags) to improve how links appear when shared on social platforms, and automatically redirect users to a password entry screen if the resume is protected, ensuring secure access to private content.
apps/web/src/routes/$username · high confidence
Startup schema verification and local storage validation
The server now performs additional checks at startup to ensure database integrity and storage availability. It verifies that the live database schema matches the declared Drizzle schema, detecting silent drift caused by manual drops or inconsistent restores; this check is non-fatal by default but can be made strict via the STRICT\_SCHEMA\_CHECK environment variable. It also validates that the local storage path is accessible and writable when using the local storage backend, failing fast if permissions are incorrect.
apps/server/src/startup · high confidence
UI package configuration and testing environment updates
The @reactive-resume/ui package has been restructured with new configuration files: a shadcn/ui components.json for style and alias management, a PostCSS config using @tailwindcss/postcss, and TypeScript configs (tsconfig.json and tsconfig.emit.json) for source and declaration emission. Additionally, the testing environment has been migrated from jsdom to happy-dom via the Vitest configuration, and global type declarations for app version and Vitest extensions have been added.
packages/ui · high confidence
Updated translations for multiple languages
Synchronized translation files for Afrikaans, Amharic, Arabic, Azerbaijani, Bulgarian, Bengali, and Catalan from Crowdin, ensuring the application interface remains accurate and up-to-date for users in these regions.
apps/web/locales · high confidence
Web app initialization and configuration overhaul
The web application now initializes with a new shadcn/ui component configuration (base-nova style, zinc colors, phosphor icons) and a dedicated index.html that implements a branded initial loader with a spinner, ensuring a smoother first paint before React mounts. The build system has been updated to target ES2023 for the library code and ES2022 for the target, while the Vite configuration now integrates TanStack Router with auto-code-splitting, Tailwind CSS, and a custom plugin to preserve Rocket Loader exclusions. Additionally, the application's internationalization is now managed via a comprehensive Lingui configuration supporting over 40 locales, and the React Query client has been reconfigured to use a custom serializer for deterministic query key hashing and data hydration.
apps/web · high confidence
Fixes
Database migration adds tracking columns to the two-factor authentication table
This change introduces a database migration that alters the \two\_factor\ table by adding two new columns: \failed\_verification\_count\ (an integer defaulting to 0) and \locked\_until\ (a timestamp with time zone). These additions support enhanced security logic for tracking failed 2FA attempts and managing account lockouts.
_migrations/20260704215942\_brave\_moon\knight · high confidence
Database migration converts UUID columns to text to preserve legacy resume IDs
This database migration alters multiple tables (including account, apikey, oauth\_access\_token, session, resume, and others) by changing their primary key and foreign key columns from UUID to text data type. This change is necessary to correctly store and reference legacy 'cuid' resume IDs that were previously stored as text but may have been mismatched with UUID constraints, ensuring data integrity for existing resume records.
_migrations/20260507144406\_fast\nova · high confidence
Fix PDF text layout, whitespace preservation, and list pagination
This update patches four underlying PDF libraries to resolve several rendering issues. In \@react-pdf\_\layout\, list markers are now kept with their content on continuation pages, and rich-text whitespace is preserved when requested. \@react-pdf\\_textkit\ now respects font-specific typo metrics for better vertical alignment and preserves literal whitespace at line edges. \fontkit\ isolates cached glyph metadata to prevent character data from leaking between text runs, and \react-pdf-html\ correctly preserves authored Unicode spaces while collapsing standard HTML whitespace.
patches · high confidence
Fix account issuer column to allow null values
The database migration for the 'account' table has been updated to remove the NOT NULL constraint on the 'issuer' column and drops the associated unique index. This change aligns the schema with Better Auth 1.7.3, allowing the issuer field to be optional rather than mandatory.
_migrations/20260906064202\_eminent\prowler · high confidence
Improved PDF font registration and fallback handling
The PDF generation hook now intelligently registers fallback fonts for non-Latin scripts (CJK, Arabic, Hebrew, Thai, Hangul) and emojis based on content detection, ensuring correct rendering of international characters and symbols. It also resolves bold font weights more accurately by registering the family's true bold face when stored weights are insufficient, and supports legacy font aliases with a fallback to IBM Plex Serif for unknown families.
packages/pdf/src/hooks · high confidence
Localized default headings in server PDF exports
PDF exports now use translated section headings (such as Summary, Experience, and Education) instead of hardcoded English labels. A new tooling script generates a section-title catalog from the application's Lingui locale files, ensuring that the PDF renderer displays headings in the user's selected language.
tooling/locales · high confidence
Restored OAuth provider schema with multi-resource and DPoP support
This database migration restores the OAuth provider schema, introducing new tables for OAuth resources and client-resource mappings to support multi-resource authorization. It also extends existing OAuth tables with columns for DPoP (Demonstrating Proof-of-Possession) binding, back-channel logout, and specific user info claims, ensuring the database structure aligns with the current OAuth registration and authorization requirements.
_migrations/20260905113135\_oauth\_provider\schema · high confidence
Server startup stability and Vercel deployment support
The server application now includes a dedicated entry point that ensures database migrations complete before initializing authentication, preventing race conditions during startup. It also adds a safety net to log unhandled promise rejections instead of crashing the entire process, improving resilience against stray errors. Additionally, the server now supports deployment on Vercel Hobby plans by providing a specific adapter that handles platform-specific requirements such as IP header sanitization, static serving configuration, and environment validation (requiring Blob storage, Redis, and encryption secrets).
apps/server/src · high confidence
Test coverage
Add semantic CSS adapter and test infrastructure for PDF generation; Added ATS export evaluation tooling to measure PDF and DOCX extraction quality; Added Playwright E2E test fixtures for authentication, resume management, and offline font diagnostics; Added tests for Turbo source-cache invalidation logic; Expanded E2E test coverage for application tracking, resume builder, and export features; New input components and extensive test coverage for the editor.
Dependencies
Upgrade to React 19 and TypeScript 7 with comprehensive dependency updates
The application dependencies have been upgraded to React 19.3.0 and TypeScript 7.0.2 across the web, server, and UI packages. This release also updates the AI SDK to version 7.0.118, the authentication library (better-auth) to 1.7.6, and the PDF renderer (@react-pdf/renderer) to 4.9.0. Additional updates include migrating to Vite 8.3.1 for the web app, upgrading Tailwind CSS to 4.3.3, and switching the package manager lockfile from npm to pnpm 12.6.0.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 43 → 57 (+14.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 81 → 74 (-7.5)
- Architecture 78 (new)
- Maturity 67 → 66 (-1.0)
- Readiness 24 → 44 (+19.9)
- Security 53 → 81 (+27.9)
- Accessibility 65 (new)
- Performance 100 (new)
Resolved (85)
- Change coupling: LaprasPage.tsx ↔ PikachuPage.tsx (packages/pdf/src/templates/lapras/LaprasPage.tsx)
- Change coupling: LeafishPage.tsx ↔ MeowthPage.tsx (packages/pdf/src/templates/leafish/LeafishPage.tsx)
- Change coupling: LeafishPage.tsx ↔ OnyxPage.tsx (packages/pdf/src/templates/leafish/LeafishPage.tsx)
- Change coupling: LeafishPage.tsx ↔ PikachuPage.tsx (packages/pdf/src/templates/leafish/LeafishPage.tsx)
- Change coupling: LeafishPage.tsx ↔ RhyhornPage.tsx (packages/pdf/src/templates/leafish/LeafishPage.tsx)
- Change coupling: MeowthPage.tsx ↔ PikachuPage.tsx (packages/pdf/src/templates/meowth/MeowthPage.tsx)
- Change coupling: MeowthPage.tsx ↔ RhyhornPage.tsx (packages/pdf/src/templates/meowth/MeowthPage.tsx)
- Change coupling: OnyxPage.tsx ↔ PikachuPage.tsx (packages/pdf/src/templates/onyx/OnyxPage.tsx)
- Change coupling: OnyxPage.tsx ↔ RhyhornPage.tsx (packages/pdf/src/templates/onyx/OnyxPage.tsx)
- Change coupling: PikachuPage.tsx ↔ RhyhornPage.tsx (packages/pdf/src/templates/pikachu/PikachuPage.tsx)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 65 more
New (430)
- $threadId.RouteComponent (cognitive 24) (apps/web/src/routes/agent/$threadId.tsx)
- $threadId.RouteComponent (cyclomatic 20) (apps/web/src/routes/agent/$threadId.tsx)
- Documentation: contradicts the code (packages/dsh-plugin/docs/spikes/2026-08-16-restrict-semantics.md)
- FileTooLong: -components/agent-chat.tsx (apps/web/src/routes/agent/-components/agent-chat.tsx)
- FileTooLong: agent/service.ts (packages/api/src/features/agent/service.ts)
- FileTooLong: components/ai-section.tsx (apps/web/src/features/settings/integrations/components/ai-section.tsx)
- FileTooLong: components/application-detail-sheet.tsx (apps/web/src/features/applications/components/application-detail-sheet.tsx)
- FileTooLong: input/rich-input.tsx (apps/web/src/components/input/rich-input.tsx)
- FileTooLong: resume/data.ts (packages/schema/src/resume/data.ts)
- FileTooLong: resume/service.ts (packages/api/src/features/resume/service.ts)
- FileTooLong: sections/picture.tsx (apps/web/src/routes/builder/$resumeId/-sidebar/left/sections/picture.tsx)
- FileTooLong: semantic/tree.ts (packages/pdf/src/semantic/tree.ts)
- FileTooLong: shared/sections.tsx (packages/pdf/src/templates/shared/sections.tsx)
- FileTooLong: stylesheet/cascade.ts (packages/resume/src/stylesheet/cascade.ts)
- FileTooLong: stylesheet/values.ts (packages/resume/src/stylesheet/values.ts)
- FunctionTooLong: $threadId.RouteComponent (apps/web/src/routes/agent/$threadId.tsx)
- FunctionTooLong: AzurillPage.useAzurillTemplate (packages/pdf/src/templates/azurill/AzurillPage.tsx)
- FunctionTooLong: DitgarPage.useDitgarTemplate (packages/pdf/src/templates/ditgar/DitgarPage.tsx)
- FunctionTooLong: DittoPage.useDittoTemplate (packages/pdf/src/templates/ditto/DittoPage.tsx)
- FunctionTooLong: GengarPage.useGengarTemplate (packages/pdf/src/templates/gengar/GengarPage.tsx)
- …and 410 more
Changes since last survey
- 300 commits — 242 feature/other, 58 fixes
By area
- docs/execution — 118 commits
- apps/web — 50 commits
- (root) — 28 commits
- (repo) — 21 commits
- tests/e2e — 19 commits
- packages/pdf — 17 commits
- .github/workflows — 8 commits
- apps/server — 5 commits
- packages/api — 5 commits
- docs/superpowers — 4 commits
- tooling/ats-export-evaluation — 4 commits
- docs/guides — 2 commits
- packages/import — 2 commits
- packages/mcp — 2 commits
- packages/ui — 2 commits
- plans/10-legacy-link-routing.md — 2 commits
- tooling/recovery — 2 commits
- .orchestration/plan-23-item-pagination-blocker.md — 1 commit
- .orchestration/remediation-issue-3350-item-pagination.md — 1 commit
- docs/changelog — 1 commit
Notable commits
- fix: Merge pull request #3484 from amruthpillai/codex/fix-geometry-e2e-opt-in
- fix: [autofix.ci] apply automated fixes
- fix: [autofix.ci] apply automated fixes
- fix: [autofix.ci] apply automated fixes
- fix: [autofix.ci] apply automated fixes
- fix: fix(ai): make provider test timeout configurable via AI_TEST_TIMEOUT_MS (#3384)
- fix: fix(api): translate copilot AI provider failures to BAD_GATEWAY (#3333)
- fix: fix(applications): handle cover letter copy failures (#3394)
- fix: fix(auth): align account schema with Better Auth 1.7.3 (#3488)
- fix: fix(auth): honor client-requested token_endpoint_auth_method during DCR
- fix: fix(builder): center preview in RTL interfaces (#3446)
- fix: fix(builder): preserve PDF glyph positions in RTL previews (#3447)
- fix: fix(builder): save pending drafts before navigation (#3453)
- fix: fix(ci): restore Docker publishing with portable runner fallbacks (#3533)
- fix: fix(components/form): resolve FormControl label target regressions (#3369) (#3387)
- fix: fix(dev): make dotenvx available through pnpm (#3537)
- fix: fix(docker): create SeaweedFS bucket with aws-cli instead of minio/mc (#3544)
- fix: fix(e2e): launch server directly so Playwright can stop it
- fix: fix(editor): avoid unsafe clipboard parsing pattern (#3474)
- fix: fix(editor): preserve literal rich-text whitespace (#3472)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
amruthpillai/reactive-resume was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a7f1829484438d9e888d2276bc11320f2b382b8f — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.