1.8.0 (2026-09-28)
- persist daily insights jobs (#341) (218e10a)
- schedule daily insights at 05:00 Europe/Vienna (#340) (fb813d8)
- unify insights into a single report (#342) (1d596d6)
1.7.0 (2026-08-28)
- add feature-flagged ml event consumer (#288) (5809688)
- add immutable release topology (#306) (192fa56)
- add ml event listener recovery (#289) (2e2914a)
- add provider circuit breakers (#295) (794148e)
- add sync event queue core (#301) (b85135b)
- complete ML event consumer cutover (#303) (5288ae3)
- enable sync event consumer (#302) (4ec3c88)
- implement architecture review improvements (#286) (a8f3ff7)
- make service event producers atomic (#300) (f059a27)
- prevent duplicate ml event processing (#290) (f35fec5)
1.6.2 (2026-08-18)
- explicitly delete both before the pip install. (8777920)
- ml: cast Decimal DB value to float in sleep consistency calculation (#278) (92e89d7)
- security: add .trivyignore for base-image Python pkgs not in app venv (#277) (9663e19)
- security: remove stale ensurepip bundle and dist-info before pip upgrade (#276) (8777920)
- security: upgrade setuptools and msgpack to fix Trivy HIGH vulns (#273) (6ea8bbc)
1.6.1 (2026-07-09)
1.6.0 (2026-06-17)
- insights: /insights page + JSON endpoints (P6) (#232) (cf88d72)
- insights: Feinschliff — Niveau-Kontext, Labels, Markdown (#235) (90134f0)
- insights: persistence + cache-aware generation (P5) (#230) (5d25c47)
- insights: rolling 7-day window + lazy per-segment generation (#236) (c857314)
- insights: wire real week-bounded metrics + reuse evidence catalog (#234) (9875ba7)
1.5.0 (2026-06-17)
1.4.0 (2026-06-16)
- insights: fail-secure post-check gate + fallback (P3) (#225) (d9d7e9e)
- insights: KI-Wochen-Insights — design docs + Schicht-1 (P0–P2) (#223) (300fdf1)
- account deletion, data export, DSGVO consent (Art. 9/17/20) (61f89e0)
- account lockout after 5 failed logins (OWASP-compliant) (1fe0c5f)
- activity page glassmorphism, light mode fix, pre-commit + CI hardening (a5cc16c)
- activity: synchronized chart crosshair, map layer selector, VO₂max sub-page (#204) (e647409)
- add abbreviation/unit explanations to RPE, Trainingswirkung and metric KPIs (23ff299)
- add activity detail page with GPS map and training effect (c585a34)
- add central settings page with connection management (c7ad182)
- add energy score backfill script + make target (833b6be)
- add epilepsy seizure diary (V15) (8eeaed9)
- add epilepsy seizure diary (V15) (034fa5d)
- add intensity minutes, training status, fix HRV trend display (401d103)
- add intensity minutes, training status, fix HRV trend display (859f3ca)
- add manual sync button with last-sync timestamp and error toasts (18b8b67)
- add new ML metrics for battery pattern and correlations (30164eb)
- add password reset request test and update password query test (a1687e6)
- add plain-language explanations to all ML detail pages (8083992)
- add readiness score info tooltip (19a259d)
- add RF confidence intervals and API route tests (642bb81)
- add running economy metrics (V13) (1f77323)
- add science explanations and sources to all metric detail pages (9f92f50)
- add Sentry DSN configuration for error tracking in ml-service a… (df7b646)
- add Sentry DSN configuration for error tracking in ml-service and sync-service (4fb0a63)
- add tests and configuration for sync-service activities and sleep mapping (104ddb8)
- add weekly volume aggregation and readiness score endpoints to API (af63969)
- aktualisiere Schlafberechnung und entferne Qualitätsfaktor für Tiefschlaf (898343d)
- aktualisiere Trainingsübersicht und verbessere Datenabfrage für Trainingslast (aed6f38)
- api: einheitliche Fehlerform via globale Exception-Handler (#170) (ce4b4b0)
- audit logging + remove garmin-tokens volume (b074efd)
- auto-backfill energy history on ML run when gaps exist (4d401d4)
- body battery pattern analysis (k-means clustering) (bcbed81)
- body battery pattern analysis (k-means clustering) (92011ba)
- CI/CD und Sicherheitsverbesserungen — Trivy Artefakte hochladen, CSP Nonce implementieren, Branch-Namen aktualisieren (cdbf286)
- CI/CD und Sicherheitsverbesserungen — Trivy Artefakte hochladen… (bfc4d1e)
- ci: add JS quality gates — Biome lint, Vitest unit tests, Playwright E2E (580b3c5)
- consolidate dashboard metrics into hero + RPE rating on activity page (0a362dd)
- custom metrics replace Garmin black-box scores (6eb533d)
- custom metrics replace Garmin black-box scores (#roadmap-1-6) (ad5db2a)
- dashboard: update styling for help button and sync action for improved UI (dfca5bf)
- db: per-service DB roles with least privilege (ADR-0001) (a8b6b1f)
- db: per-service DB roles with least privilege (ADR-0001) (e9d5738)
- e2e: implement end-to-end testing workflow and update test configurations (e0f0db1)
- email-verification at registration (2c18d6d)
- encrypt Garmin/LibreLink tokens at rest in DB (a06811e)
- enhance backfill logic to include additional custom metrics for energy scores (fd2b577)
- enhance body battery model with REM sleep data and improve backfill processes (2f8fdb6)
- Enhance evidence catalog with EN 62366-inspired fields and update dashboard (edc6519)
- Enhance metrics rendering and improve sync-service shutdown handling (8cc1cb4)
- erweitere Schlafmetriken um Einschlaf- und Aufwachzeiten sowie Diagramme für Schlafrhythmus (8204484)
- erweitere Wochenparameter auf 56 und verbessere Body Battery-Diagramm-Logik (7fe25e1)
- EU compliance — consent_terms, consent_age, accessibility statement (f52609e)
- expand seizure risk indicator with HRV, body battery, resting HR and vigorous training flags (cb9703d)
- extend ML models + add scientific evidence transparency (f5a50ac)
- Extrahiere Token-Logik in auth_tokens.py und verbessere Sicherh… (5c7eb67)
- Extrahiere Token-Logik in auth_tokens.py und verbessere Sicherheitsüberprüfungen in auth.py und epilepsy.js (0775ce7)
- glassmorphism dashboard redesign and fix training status sync (71e3d9b)
- hardening: app-rules compliance — structlog, caching, CSP, fonts, Docker (96fb992)
- help: enhance help articles with improved search functionality and layout adjustments; add metrics overview script (fbbfd96)
- hero card permanent above tabs + fix stress label + 100% coverage (ccaf546)
- hero card redesign + chart time navigation (49aaab0)
- implement 4 quick-win ML metrics (ACWR, Training Monotony, Sleep Consistency, SpO2 Trend) (b252bd2)
- implement ACME/Let's Encrypt support for TLS certificates in Traefik (adc9c7b)
- implement database structure and inference models for health metrics (625149a)
- implement epilepsy mode update and enhance risk indicator presentation (c7bb1db)
- implement historical backfill for new ML metrics (body battery, stress, running economy, hrv recovery) (7a513d2)
- implement password reset flow and update environment file structure (6fad099)
- implement training load calculation and update sync settings (c86a99d)
- implement V17 quick-win metrics (body battery, stress score, running economy, hrv recovery) + spo2 settings (c25d7f0)
- implement weekly statistics and readiness score endpoints, update activity and dashboard templates (d63229d)
- initial PulseBase commit (2a9fb72)
- integrate LibreLinkUp glucose data from Libre 3 CGM sensor (54ad402)
- Konfidenzintervall auf der Readiness-Seite anzeigen (cb95f64)
- metrics: enhance metrics with summaries and recommendations (f13399f)
- metrics: update readiness metrics to include training date and adjust training sample count display (cdccc8c)
- ML Analytics Phase 1 — ml-service infrastructure (5188d53)
- ML Analytics Phase 1 — ml-service infrastructure (90367c6)
- ML Einblicke Widget im Dashboard (c8aeed6)
- ML Einblicke Widget im Dashboard (PR B) (cd235cc)
- mobile-first UI redesign and activity date-range filter (90c56d0)
- ops: verschlüsselter Backup-Container (age) + TimescaleDB-korrektes Restore (Wave 16 PR-B) (#171) (757d7db)
- password-reset flow + per-service secrets isolation (07cd943)
- Phase 1 chart polish — gradients, tick limits, pointRadius, touch UX (6a86419)
- Phase 2 score-cards & surfaces — surface-elevated, scoreLabel, KPI delta (90197d8)
- Phase 3 inline sparklines — 14-Tage-Trend in Hero-Tiles (0de9f80)
- Phase 4 navigation — bottom-nav, tab merge, /metrics overview (e7fd3e8)
- profile: add weight_kg field for VO₂max and W/kg calculations (#202) (052a4f8)
- readiness score info tooltip (e059eb4)
- redesign hero card + merge readiness sub-pages into combined view (d42a689)
- redesign hero card + recalibrate energy metrics (c7d815c)
- redesign UI — opaque cards, type scale, chart palette (a905f6a)
- refactor: implement structured logging and Dockerfile improvements across services (b9f582a)
- replace dashboard hero with bento box layout and add metric detail pages (745052a)
- replace Garmin-based readiness with own energy metrics + add sleep quality factor to cognitive score (dc33773)
- report: add architecture review report for PulseBase (e7b5701)
- restore 4-tab layout (Heute/Training/Verlauf/Erholung) (01a5fc4)
- RF confidence intervals + API route tests (45bbc8f)
- RF median imputation + extended correlations (sleep/BB → resting HR) (e61d196)
- RF median imputation + extended correlations (sleep/BB → resting HR) (40dc257)
- security hardening, network isolation, Caddy integration (c9899f2)
- separate ML detail pages with feature importance (f49ceb9)
- show confidence interval on readiness ML page (e44afaa)
- style: Motion-Fundament (reduced-motion + Tokens) + Wow-Polish (#162) (5599938)
- style: Skeleton-Screens für Hero + Aktivitäten (kein Layout-Shift) (#163) (1215a4c)
- sync-service: add health server and improve fernet key handling (f2c5144)
- sync-service: add health server and improve fernet key handling (ddf1b16)
- Tailwind CSS migration + Slate/Emerald redesign + sport type fix (#45) (fb23449)
- tests: Wave 6 — Tests & Zuverlässigkeit (H-04, H-05, M-14, M-30, M-31, L-12, L-22, L-23) (ac4d679)
- tests: Wave 6 — Tests & Zuverlässigkeit (H-04, H-05, M-14, M-30… (947e78a)
- trigger ML inference after sync + add training load as readiness feature (0146622)
- trigger ML inference after sync + training load as readiness feature (e027f8b)
- ui: clean up UI components and remove bottom navigation; enhance dashboard layout and ML insights display (2689948)
- ui: Dashboard ↔ Metriken — klickbare Charts + kuratierte „Deine Metriken"-Leiste + Verwandte-Metriken-Block (#179) (1171fc3)
- ui: Dashboard-Kopfbereich neu — sticky Top-Bar, Segmented Zeitraum, Sync-Pill (#176) (c9e02a9)
- ui: hero card redesign + ML metrics consolidation (0a46c1f)
- ui: KI-Transparenz im Dashboard (UX-Review PR2) (280c88b)
- update CI configuration, enhance security scanning, and improve error handling in database operations (1b04e8a)
- update Dockerfiles to include apt-get update and upgrade (8d3fde4)
- Update documentation for testing, security, and architecture improvements (2ba45c7)
- update monitoring setup and external service configurations (ac6f9b5)
- update security policy and documentation for public deployment (5abd67a)
- update sleep score metric routing and enhance metric descriptions (4c53b73)
- ux: Item-Level-ML-Feedback (👍/👎) auf KI-Tiles — UX [D3-1] (825a390)
- ux: PR3 — Anfälle editierbar, Bestätigungsdialoge, Onboarding-Hinweis (4078f1d)
- ux: PR3 — Anfälle editierbar, Bestätigungsdialoge, Onboarding-Hinweis (5815fd6)
- ux: PR4 — ML-Feedback (👍/👎) + Rest-Lows [A-6]/[D4-2] (685f5f1)
- ux: rename stress score to Autonomer Stressindex, consolidate Body Battery + Readiness (#205) (be16ce5)
- ux: Rohdaten-Hinweis bei ML-Leerzuständen — UX [D4-2] (39c7e35)
- Verbesserte Protokollierung und Fehlerverarbeitung in allen Die… (0bb883c)
- Verbesserte Protokollierung und Fehlerverarbeitung in allen Diensten (6624ea1)
- Wave 10 R1 — Security Quick Wins + 100% Coverage (alle 3 Services) (b889cda)
- Wave 10 R1 — Security Quick Wins + 100% Coverage (alle 3 Services) (870ce4f)
- Wave 10 R3 — Architektur & Betrieb (c83c544)
- Wave 10 R3 — Architektur & Betrieb (M-45, M-46, M-48, M-49, L-40, L-43) (effb1bc)
- Wave 10 R4 — Tests (L-47–50, M-53, M-55) (82cf3fe)
- Wave 10 R4 — Tests (L-47–50, M-53, M-55) (0331ee4)
- Wave 10 Runde 5 — Code-Qualität und neue Tests hinzugefügt (6ea52d6)
- Wave 7 — Observability & Docker-Härtung (M-20, L-01–05, L-20, L-24, L-25) (c27507e)
- Wave 7 — Observability & Docker-Härtung (M-20, L-01–05, L-20, L… (cbaaefd)
- Wave 9 R4+5 — Code-Qualität, CI/CD & Observability (340da7a)
- Wave 9 R4+5 — Code-Qualität, CI/CD & Observability (2b87a16)
- Wave 9 Runde 2+3 — Graceful Shutdown, Tests, E2E Coverage (1dfe4fc)
- Wave 9 Runde 2+3 — Graceful Shutdown, Tests, E2E Coverage (87c3b10)
- wire recovery chip to metrics page + chip UX fixes (6020c2d)
- a11y: Fokus-Ring-Kontrast anheben — UX [A-6] (0c2c0db)
- activity: korrigiere Schrittlängenberechnung und erweitere Präzision in der Datenbank (ad24f0c)
- add stress sparkline to hero card dots (avg_stress from daily data) (248d9ec)
- add type ignore comments for Settings instantiation in db and main modules (39b4f84)
- Aktualisiere Importpfad für Authentifizierungseinstellungen in den Tests (9a482f7)
- body_battery_custom KPIs — show '0' instead of '−0' for zero drains (ee50f50)
- body_battery_custom metrics page — update KPIs + formula to fresh-state model v2 (3d54abc)
- cast session user_id to int in require_user; switch to Renovate (1cdabce)
- CI — mypy explicit-package-bases, trivy ignore-unfixed, bandit assert→raise (ff546bf)
- CI e2e — env/.env.app + FERNET_KEY migration (f4e8b10)
- ci: exclude *.md from PR size check (525f589)
- ci: exclude lockfiles from PR size check, lower sync coverage gate to 50% (938ccd1)
- ci: remove quiet flag from Playwright browser installation (9d9aef6)
- ci: suppress bandit B108 + semgrep false positives; move sync DB queries to repo layer (1a1198d)
- ci: wave 3 — CI/CD hardening (8afe713)
- correct docker image versions to match existing data (04a0002)
- db: drop hardcoded DB name in V24 (broke garmin_test) (f295cb1)
- docker: add missing networks configuration for db-test service (0f1afa4)
- dynamic feature set for RF model when hrv_last_night has no data (204023f)
- ensure numeric rounding in weekly stats calculations for distance and duration (c8b24f3)
- Entferne nicht verwendete pnpm-workspace.yaml Datei (4bfdc9d)
- epilepsy: epilepsy.js als ES-Modul laden (b295b28)
- exclude fastapi 0.136.3 (MAL-2026-4750 supply chain) (7919484)
- gap detection checks each model independently (body_battery_custom + stress_score_custom) (01e8e5e)
- infra: Wave 2 — Docker reproducibility, healthchecks & security hardening (#181) (c59e637)
- logging: prevent credential disclosure in Garmin and LibreLinkUp token logging (d6b58db)
- logging: prevent credential disclosure in token login warning (15fb257)
- make db + add make logs-ml, make build-ml (50517f1)
- makefile: remove quiet flag from Playwright browser installation (1c374e2)
- median imputation for readiness inference + dedup sleep sessions + always refresh readiness today (a1fb84c)
- ml: circular sleep std, HRV battery fallback, running economy thresholds, stress 75/25 blend (#201) (767791e)
- mypy arg-type für sentry_sdk.capture_message level-Parameter (a7689a0)
- mypy type: ignore[override] auf def-Zeile für NonceTemplates (ab52e3d)
- pass cutoff date as Python date object in ml-service queries (50dbf75)
- pnpm-workspace.yaml packages field + esbuild allowBuilds (997680e)
- readiness tooltip extends right instead of left (b1bde64)
- reduce test coverage failure threshold to 15% (49e4fb9)
- regenerate uv.lock after package rename garmin-* → pulsebase-* (50572fc)
- resolve HRV sync bug, align RF labels with energy metrics, and clean up inconsistencies (32f2d64)
- security+bugs: wave 1 — bug fixes & security quick wins (798f0a8)
- security+bugs: wave 1 — bug fixes & security quick wins (3effe23)
- security: address top-10 findings from app-eval audit (7ede441)
- security: address wave-2a findings from app-eval audit (38650c5)
- security: address wave-2b findings from app-eval audit (a92756d)
- security: address wave-2b findings from app-eval audit (f2dfb08)
- security: address wave-2b findings from app-eval audit (7fb5f2f)
- security: address wave-2b findings from app-eval audit (e9a00f0)
- security: Wave 1 — token TTL, Sentry gaps, backup hygiene, GDPR consent audit (#180) (b7300da)
- security: wave 2 — CSRF protection + reset token invalidation (95025e9)
- semgrep: drop exc arg from token-login warning to eliminate credential-leak rule (26691bc)
- semgrep: move nosemgrep comments to preceding line for multiline logger calls (3f6fec3)
- semgrep: remove PII and credential-leak false positives from logger calls (08a26bf)
- specify type for password_hash in login function (2d6b912)
- starlette 1.0.0 → 1.2.1 (PYSEC-2026-161); exclude data/*.json from PR size check (4a6ba78)
- style: Tailwind-Purge-Bug, Light-Mode-Kontrast + accent-Single-Source (#161) (c685eb8)
- suppress bandit false positives in libre client (258d58c)
- sync: support new Garmin API metric format + backfill script + make targets (#203) (6e14788)
- tests: update save_consent tests to use test IP hash instead of secret (f594b12)
- training-load: correct EWM alpha factor + readiness arc redesign (d136f35)
- type=module ergaenzt, identisch zu dashboard/help/metrics. (b295b28)
- ui: Zeitauswahl-Labels (1W·2W·1M·3M·1J) + Onboarding-Dismiss CSP-fest (#178) (0388fb3)
- update CI workflow to trigger on all branches and add concurrency settings (b29f983)
- update CI workflow to trigger on main branch only (56302f3)
- update logging configuration to write logs to stdout and add Sentry initialization (4fb0a63)
- update pip-audit commands to use directory paths (897d20b)
- update readiness test fixture to use energy-based labels (4acb433)
- update test import after anomaly function rename (2fb83a8)
- update test to reflect median imputation in predict_tomorrow (e48542f)
- Wave 8 — Code-Qualität: Rückmeldung zu fehlenden Return-Annotierungen in aktualisiert (f6eda32)
- wave-6: docs, cosmetics & minor fixes (L2, L5, L6, L18, L25–L28) (#185) (3157502)