Changelog
Every version of Gaitro, newest first. We build Gaitro in Gaitro, so each entry is the summary written for the person who shipped that change, when they shipped it.
October 6, 2026
- v61
Shared Knowledge can't carry instructions to other agents. Before a lesson is shared to the common pool that other companies' agents read, its text is scanned for the same hidden-instruction patterns guarded in agent instruction files — telling an agent to ignore its instructions, hide things, run code from the internet, send secrets, or skip checks, plus invisible characters. A lesson that reads like directions to an agent is kept private instead of shared.
- v60
Removing someone, or revoking a login, stops its agents at once. When a person is removed from a company, a company login is revoked, or a password is reset, any agent still working under it stops immediately. An agent login is also re-checked on every request, so it can't keep acting after its person has left the project or its login is gone.
- v59
Secrets stay out of untrusted check runs. A project's vault values are now handed to a check only when the code it runs is trusted — a run on the live version, a publish, or a draft owned by someone who can publish — so a draft from someone who can only suggest runs without them. Agent-set secrets default to preview, and production-only values are never set in a check. The vault's promise holds: secrets are used but never read back.
- v58
SEO Phase 4 on gaitro.com. Two guides answer what people search for: running several coding agents on one repo without conflicts, and reviewing AI-written code without reading the code. Each has its own page, a markdown copy for agents, and a place in the sitemap, llms.txt and the footer. A changelog at /changelog lists every version of Gaitro that's live, newest day first, in the summaries written when each one shipped; a version published after the running release waits for the next deploy. Public projects are titled by their name and owner in search results and described by their README, every project page names its project in the browser tab, and app.gaitro.com has a sitemap of its public projects. The website's wording on claims now matches the product: what an agent edits is reserved as it saves.
- v57
Projects made before the current GAITRO.md can bring it up to date in one click: Settings says whether the project's agent instructions are current, and for an owner, Update GAITRO.md opens a ready draft with the current text, which ships like any other change. A project whose file is already current isn't touched.
- v56
The website reads well on a phone. The GitHub comparison and Pricing's Compare everything show one card per row on narrow screens, instead of tables cut off at the side; the tables in the docs and on Privacy stack into one block per row, each value labelled with its column; and the header has a Menu button on phones (Explore, Pricing, Docs, Log in) instead of links hidden under the logo. The comparison's row on collisions now says what's true: what each agent edits is reserved as it saves. The browser suite now checks every website page at phone width for text cut off at the side.
- v55
Waiting for code a draft never edited no longer stops it: marking ready drops a wait for something it asked for ahead and didn't touch, and the publish gate counts only waits for code it changed (by its key, its old key, or a whole file it changed in). Found shipping #54, which waited on package.json without editing it.
- v54
Every deploy now checks production from the outside before calling itself done: every website page answers, pages come from the fast edge copy, security headers are right, the app is on the new version, and private things stay private. If anything's off, it stops and says how to go back.
- v53
The command-line tool now updates properly. Every deploy gives it a new version number, so reinstalling always gets the latest, and an older copy says once a day that a newer one is out and how to update (agents using it through MCP are told too). 'gaitro version' shows which one you have.
- v52
If someone opens Gaitro just as it goes to sleep, the 'starting' page now says it's saving its work first and may take a few minutes, instead of promising half a minute. The logs now record how long each stop and start takes.
- v51
Deploys should no longer show errors at all: two more ways the app's container can briefly be unavailable while Cloudflare swaps it are now waited out and retried, instead of showing an error for a few seconds. Also, the background helper that reserves an agent's edits now stops as soon as its change is shipped.
- v50
Fewer behind-the-scenes writes and reads: an agent's reserved code is renewed only when half its time is used instead of every few minutes, the minute-by-minute health checks use database indexes instead of reading every check run, and a project's page shows the newest 25 versions with older ones a click away instead of loading the whole history.
- v49
Saving each project's code to storage gets cheaper as projects grow. After one full copy, each save is just what changed plus the list of branches, so a save, and a push waiting on it, takes about as long for a big project as a small one. Restoring rebuilds the full copy and checks it's complete, falling back to an earlier save if anything is missing. A fresh full copy is made at least daily and after a secret is removed from history.
- v48
Pages that show code do less work: when a page shows the same version of a file again, for example as it refreshes live, Gaitro reuses what it already worked out (the file, its history, its colors) instead of asking git and the highlighter every time.
- v47
Publishing does less behind the scenes: after a change goes live, Gaitro re-reads only the tests that change touched, for checks that still run, instead of every check ever written.
- v46
No more error pages while Gaitro deploys. When a deploy swaps the app's container, a request that reaches the old one as it stops is answered by the new one, or someone opening a page sees the 'Gaitro is starting' page, instead of a Cloudflare error. About 30 seconds of errors happened at each deploy before.
- v45
Knowledge becomes an add-on and old activity is cleaned up. Each project has a Knowledge on/off switch in its settings; new projects start with it off, and existing projects keep it on, so nothing changes for them unless an owner turns it off. Activity older than 90 days is deleted automatically, except the decision log and the record of what went live.
- v44
Agents get far less to read. The instructions file every agent reads in this project (GAITRO.md) is now one short path, start a change, edit, ship when the person says so, in about 340 words instead of almost 900; the rest is behind 'gaitro help <topic>'. 'gaitro start' begins a change with plans and checks optional, and 'gaitro ship' saves unsaved work itself before shipping. Also fixes 'gaitro check keep --undo' and 'check add --keep', which didn't take effect.
- v43
The project page is now a live map of who's working on what: each open draft lists the files it's changing, updating as agents edit, and a file two drafts are both changing is highlighted on each with the other draft's number, so a collision is visible before anyone hits it.
- v42
Claims now follow the edits. While an agent works, Gaitro reserves the code it changes as it saves (from the MCP server, or a small background helper the CLI starts with each draft), so another agent hears about an overlap within seconds instead of at its next save, and nobody has to remember to claim first. When an agent edits code another draft is working on, it's told right away and its draft simply waits its turn: it gets the code when the other draft ships or lets go.
- v41
Claims follow what code really uses. When an agent changes code, Gaitro reserves for reading only what that code imports or defines alongside it (following re-exports, so database tables still count), instead of anything anywhere with a similar name; on Gaitro's own code that's about a third as many links. A draft marked ready lets go of what it only read, and a draft waiting for review no longer holds code indefinitely: its claims lapse like anyone else's, so another agent isn't kept waiting on a slow review.
- v40
Checks no longer pile up. A draft's checks prove that change and retire when it ships (they stay on the draft as the record), unless someone keeps them: then they join the project's checks, and a command the project already runs isn't added twice. Keep a check from the draft page, with gaitro check keep, or by accepting a suggested check. A draft no longer has to bring a check of its own. Gaitro warns when a test only reads source code as text. Owners can archive project checks with a reason that goes in the log.
- v39
Check runs cost less. When several checks run the same command (the typecheck, the unit tests), it runs once and they all get its answer, and check minutes count it once. Passing checks no longer store their output; failures still do. A command that already ran on the same code isn't run again for another check.
- v38
Agents get shorter answers from Gaitro. Status lists only the draft's own checks and anything failing, and counts the rest. MCP replies are compact. Sync no longer lists bookkeeping claims, and new code isn't flagged as 'edited before claiming'. Agents are asked to replay only when their change actually conflicts with the live version, and a publish notifies only drafts it conflicts with instead of every open draft. A command on a shipped draft now says 'Draft #N shipped as vN'.
- v37
Fixes for bugs found while measuring Gaitro. Bots looking for WordPress or .env files get a 404 at Cloudflare and no longer wake the app or keep it awake. gaitro watch and the MCP server no longer crash or log 'undefined' while checks run. gaitro ship now waits for checks that haven't run (and starts them) instead of refusing. A suggested check you say No to stays gone. Risk reasons name each file once, and a deployment setting counts as a normal change rather than a secret.
- v36
Sleep is switched on: after 15 quiet minutes with nobody connected and nothing running or due, the app's container sleeps; the next request or a job coming due wakes it. Set APP_SLEEP_AFTER_MINUTES back to "0" to switch it off.
- v35
Two fixes to the edge cache from v33, found by checking production: a browser holding a file Cloudflare compressed (its ETag made weak, W/…) is told again that it hasn't changed (304), as before v33; and pictures from the cache give the browser the app's own caching, while Cloudflare's cache keeps them for a day.
- v34
The website's copy answers from Cloudflare's cache in each data center instead of reading R2 on every request (which made copied pages 150–190 ms against the app's ~100 ms). Static files are kept for good, pictures per build, pages per copy so a new copy shows at once, and what the copy holds for half a minute. Each visitor still gets their own nonce and theme; 304s still work.
- v33
The app's container can sleep when nobody's using it. The minute cron looks in through App.tick (never through fetch, so its look isn't anyone using the app): health and alerts while the app is up, and a crashed one is started again as before. After APP_SLEEP_AFTER_MINUTES with no requests, it asks the app (/api/health?idle, worker secret only) and sleeps only if no one is connected (live pages, gaitro watch/wait) and no job, check run or agent is running or due; it stops the way a deploy does, saving every repo. The next request wakes it, with a starting page for someone opening a page; a queued job coming due wakes it too; the worker expires claims as soon as it starts. Off ("0") in wrangler.jsonc until switched on.
- v32
gaitro.com no longer waits on the app's container. The Worker keeps a copy of the website in R2 (site-copy/ in the repos' bucket): every website page, the pictures they show (each screenshot size, as WebP) and every /_next/static file. The minute cron has it copied when it sees a new build, and the pages every 30 minutes, only while the app's container is up (copying never starts it). gaitro.com's pages are served from the copy, each with a fresh script nonce and the visitor's theme; website links load the next page from it; /_next/static comes from it on both hosts, so old tabs keep their files after a deploy. Anything the copy doesn't have still comes from the app. Tried against a real production build in a headless browser: 120 of 120 requests from the copy, no blocked scripts, no console errors. To stop serving from the copy: delete site-copy/meta.json (cloudflare/README.md).
- v31
A test-only fix so CI passes reliably: the browser suite's live refresh flow waits for each effect (up to 20 s) instead of fixed pauses, and starts its checks only once the page's stream is open.
- v30
Draft pages read well. Generated files (lockfiles, drizzle-kit's schema snapshots and journal, minified bundles, source maps) are one symbol each: a new migration lists one change for its snapshot instead of 1,000+, and the snapshot's table names (session, cli_login…) no longer read as sign-in code; files already indexed key by key are read again whole, which also shrinks the code index. Risk reasons summarize: each area names up to three things per file and three files and counts the rest; database files and tables group like public APIs. On a phone, the plan's Done labels keep their width; a new browser check fails on any short word broken across lines, which also fixed a person's role buttons (44px tall, Remove below them on a phone) and the Knowledge tab's Current marker.
- v29
Cuts database transfer and app CPU without losing a feature. The code index is kept in memory per published version, so claims and syncs make one tiny read instead of loading every symbol (about 20 MB for Gaitro). Finished drafts skip the publish check. Live pages: a hidden tab stops listening and catches up once when shown; each page re-renders only for events it shows; the 'waiting on you' count updates itself; links load on hover, focus or touch instead of after every refresh (a timeline refresh went from 16 extra page loads to 4, none of them whole draft pages; clicks stay ~50 ms). Profile photos move to their own table and their own cached, signed-in-only address, so the session's user read and every page no longer carry the picture. Migrations: 0011 adds the table (run before the deploy); 0012 moves existing photos (reviewed by Nate; run after the deploy).
- v28
Two-step sign-in. From Your account you can turn it on: enter your password, scan the QR code with an authenticator app (or on your phone, open it straight in the app), and enter one code to prove it works; you get ten backup codes, shown once. After that, signing in asks for the 6-digit code after your password, with 'Lost your phone? Use a backup code' (each works once) and 'Don't ask on this device for 30 days'. Turning it on needs a confirmed email, and turning it off or making new backup codes needs your password. No email link can sign in around it.
October 5, 2026
- v27
A fix to the automatic test run on GitHub: the demo data is reset between the browser tests and the command-line tests, because the browser tests now change it (they move an email and turn on two-step sign-in). This is what stopped the Your account update from passing on GitHub.
- v26
A new Your account page, from the account menu. Times of day across Gaitro now show in your own time zone instead of the server's (UTC): it's picked up from your browser the first time and can be changed on the page. You can change your name and add a photo, which shows in the account menu. You can change your email: the change is approved from your current address first and then confirmed from the new one, and those links only finish for someone signed in. And you can see the devices you're signed in on, sign any one of them out, or sign out everywhere else. Mail errors no longer carry an email address into the logs.
- v25
Three more improvements for phones. Tab rows that don't fit now fade at the edge with more tabs past it and keep the current tab in view, so Knowledge or Settings is never silently cut off; the project settings menu does the same. Everything you tap (buttons, tabs, menu items, file rows, fields) is at least 44 pixels tall on phones and touch screens, and fields use 16-point text so iPhone Safari no longer zooms in when you tap one; address fields drop below their prefix instead of being squeezed. A draft's progress shows as one line and a bar on a phone instead of five steps wrapping over three lines. Browser tests check all three on a phone-sized screen.
- v24
On a phone, cards no longer push off the side of the screen. Long file paths and names, which Gaitro's own project is full of, now wrap inside their card instead of making the whole page wider than the phone. Every app page, public project page and admin page was checked at phone width with long content; the file lists and four other places that still overflowed are fixed. A browser test now opens every page on a phone-sized screen with a long path in it and fails if any page scrolls sideways, so this can't quietly come back.
- v23
Finishes the redesign inside the app. Knowledge, a single version, a check run and a choice now group their sections on cards with a side panel, like the timeline and the rest of the app, instead of a flat page with lines between sections. Nothing about how they work or what they say has changed.
- v22
Six fixes found by using Gaitro on its own code. There's a new gaitro pull that downloads the published version, so it can be deployed or copied anywhere, and opening a project again now brings it up to date. Plan steps can be ticked by their number or their words, and Gaitro says when one doesn't match. When an agent edits something before claiming it, sync now says so plainly, separately from the routine claims it adds. Restyling a sign-in or payment page no longer counts as high risk, while any change to how sign-in or money works still does. Checks now know which pages and components their tests read, so editing a website page runs the website's checks straight away. Symbol search can be limited to one file or folder and shows every match, not just the first 40.
- v21
Gaitro now looks like the official brand kit 1.0, on the website and in the app. The logo is the boat on its wake under the Farnor star, with the lettering as drawn artwork instead of typed text. The colours are Deep Navy, Wake Blue, Mist, Farnor Brass and Ivory, and the fonts are Inter and IBM Plex Mono. The website is now light ivory (navy at night) with the same words as before: a seascape under the opening, a navy safety section, and fresh screenshots of the app in its new look. The browser-tab icon, home-screen icon, the picture shown when a link is shared, and the emails all match. Nothing about how anything works has changed.
- v20
Fixes the docs, Privacy and Terms on the live site. Since the production image was made smaller, it no longer carried the folder that holds the docs and legal pages, so /docs, every docs page and its markdown copy, llms.txt, llms-full.txt, the sitemap, /privacy and /terms all show an error. The folder is back in the image, and a new check fails if the image ever leaves out a folder the app reads at runtime again.
- v19
Two kinds of test that were missing. A new suite checks who may do what through the API: each role, tokens limited to one company or one project, a draft's agent token, and people from another company; it found no gaps. And the browser test suite now runs on every pull request on GitHub, against the running app and worker, so a page that breaks is caught before it ships. Getting it to run there needed Chrome found on Linux, more time for Chrome to start, the browser tests run before the CLI tests (whose data changes what the demo shows), and more time for Knowledge hints on GitHub's busy machines.
- v18
The app's container gets lighter and faster. The Cloudflare Worker used to check the container's health before nearly every request; now it checks once when the container starts. The production image is built in two stages and carries only what runs (1.3 GB instead of 2.05 GB), with the worker built into plain JavaScript; the build now refuses to finish if that JavaScript imports anything Node can't load, which caught a crash that would have stopped the worker. The container goes from one CPU to two, and the background worker runs at lower priority than pages, so a busy worker no longer makes the site slow.
- v17
The website now has a Privacy policy, Terms of service, and a page comparing Gaitro with GitHub, all linked from the footer, and extra check minutes are on the pricing page. Privacy says, in plain words, what Gaitro collects and why; that there are no ads or trackers and only sign-in and theme cookies; which companies handle data (Cloudflare, Neon, Stripe, and Anthropic for the plain-words explanations of changes); that nothing is public unless you choose; that closing an account deletes its data within 30 days; and that Gaitro is for people 16 and older. The Terms are between customers and Farnor Labs, LLC under Arizona law: your code stays yours, you decide what ships, plans renew monthly and can be cancelled any time with no refunds, what isn't allowed, and limits on liability. The GitHub comparison is honest about where each fits. Pricing now has an Extra check minutes block ($18 for 1,000, good for 12 months) and a row in Compare everything. The sign-up form says creating an account accepts the Terms and Privacy policy.
- v16
One company can no longer hold up everyone else's background work. Each job now records its project, and the worker takes turns: the project with the fewest jobs running goes next, and while others are waiting no project runs more than two at once. Before, one company with slow checks could take all four slots. Separately, at most four claim locks are held at once, so a burst of agents claiming code across many projects can't use up the database connections and hang the app.
- v15
Gaitro now reads far less from its database, after Neon warned we had used 90% of a month's transfer in two days. While checks run, only the page of that draft refreshes, at most every eight seconds (before, every open page of the project refreshed on every step of every run). Pages read each check's newest result and only show output for failures, instead of every result's output from the last dozen runs; the project Checks page reads about a seventh of what it did. The count of things that need you, shown on every project page, uses a light check instead of the full publish rules. Lists of drafts leave out each draft's full list of changed parts. And gaitro wait listens for the run to finish instead of asking for the whole status every five seconds.
- v14
The docs are now nine short pages instead of one long one: Get started, Connect your agent (Claude Code, Codex, Cursor), Already building, The workflow, Checks, Knowledge, Public and private, and full references for the CLI and the MCP tools. Each has its own title and description for search engines, and a sidebar to move between them. Each page is also available as plain markdown at the same address plus .md, for people's AI agents to read. gaitro.com/llms.txt lists every page with a one-line description for AI assistants, and gaitro.com/llms-full.txt has all of them in one file. The CLI and MCP references are checked against the real command and tool lists, so they can't fall out of date.
- v13
Gaitro's admins now hear about trouble. Every minute the app looks for a publish stuck in the queue, a check run that hasn't moved, background jobs nobody is picking up, a repo whose changes aren't saved, and the check sandbox failing again and again; a rejected Stripe webhook raises one straight away. Every admin is emailed once when a problem starts, again if it lasts six hours, and when it clears, and Admin has a new Alerts tab. When the whole app stops answering, the Cloudflare Worker emails the address in ALERT_TO, which needs setting once.
- v12
The website now has an About page and a Security page, both linked from the footer and in the sitemap. About says what Gaitro is, why it exists, who it's for, and that Farnor makes it, with info@gaitro.com for questions. Security lists only what Gaitro does today: keys encrypted in a vault nobody can read back, a fresh sandbox for every check run, safety checks on every change, projects private by default, shared fixes that never include your code, how signing in works, that your agents run on your own machine, and where data lives. It asks people to report problems privately to info@gaitro.com, and gaitro.com/.well-known/security.txt says the same for security researchers. Each claim is tied to the code that makes it true, so a check fails if the code ever stops doing what the page says.
- v11
Owners can now ship a draft before its checks finish, for when it can't wait: under a blocked Ship it button there is 'Ship without waiting for the checks', which asks why. It only appears when unfinished checks are all that's in the way, never over a failed check, a safety finding or a missing approval, and never for someone who isn't an owner. The reason and the checks that hadn't finished go in the decision log, and the change goes live on its own, without the publish queue running checks. Separately, a deploy now only counts as done once the new code is the code answering.
- v10
Check minutes now work the way the plans promise. Setup time counts. The minutes a change uses now include setting up what its checks need, not just running them, because both keep Gaitro's sandbox busy. Extra minutes. Companies on Pro and Pro Plus can buy 1,000 extra check minutes for $18, through Stripe. Extra minutes are used only after the month's plan minutes run out, the pack that expires first going first, and each pack lasts 12 months. Running out. When a company has no minutes left, new checks wait instead of running, and it's told why: Free is offered Pro, Pro is offered Pro Plus or a pack, and Pro Plus is offered a pack. Owners get an email at 80% and 100% of the month's minutes, and when everything runs out, each once a month. Plan & billing shows the month's plan minutes, then extra minutes: each pack's balance, what this month took from it, and when it expires. The pricing page and the cost answer on the home page mention packs.
- v9
Security fixes from the audit. Next.js goes to 16.3.8, which fixes a critical flaw in the code that draws gaitro.com's share image. When something unexpected goes wrong, people and agents now see a short reference instead of internal details (database text, file paths), and the details go to our logs. Browsers are told to use HTTPS only, and to run only the app's own scripts, so nothing another company or an agent wrote can run on a page. Rate limits now cover the CLI sign-in, the name checker on sign-up, repo uploads and starting checks by hand; going over gets a clear 'try again in N minutes'.
- v8
Explore can no longer show the check sandbox's own errors as unsolved problems. When the sandbox itself fails (a container that stopped or never started), Knowledge no longer opens a question about it, because that says nothing about any package. A database update, reviewed by Nate Warner, closes the questions opened that way before the fix. It deletes nothing and leaves every other question alone. In production the one such question has already been closed by hand, so there it changes nothing.
- v7
The website now says what Gaitro is, in one voice. There's one tagline everywhere: "The multiplayer code repository for people and their agents." It's in the footer, the sign-in and sign-up pages, the README and the CLI. The home page explains what Gaitro is in plain words, then adds one short line for developers. A new "Questions" section answers eleven things people ask before signing up, such as how Gaitro differs from GitHub, which agents work with it, whether you need to code, privacy, and cost. Search engines and AI assistants get those same answers word for word. The pricing page explains what a check minute is.
- v6
A test only: the check that a draft discarded while the publish queue tests it never goes live now gives the queue code it has to check, since the queue no longer re-runs checks it already has answers for.
October 4, 2026
- v5
Checks now say what they are doing: the draft page shows the step (starting, installing, or which check is running), a moving bar, and about how long is left, worked out from how long the same checks took last time. Each check shows its answer as soon as it has one. They also take less time: a check that already passed on exactly this code isn't run again (marking ready and publishing used to run everything twice more), a newer run replaces the one under way at once, a run cut off partway keeps what it learned, and the sandbox gets four cores instead of half of one. Long runs no longer fail at five minutes. Pages load about three times faster: their database reads go out together instead of one after another, and the count of things that need you no longer holds the page up.
- v4
The website is now set up to be found by search engines and AI assistants. Each page has its own title and description, and names gaitro.com as its one address. There's a robots.txt that welcomes search, AI answers and AI training on the website (the app keeps crawlers out of private areas), a sitemap, a favicon, a home-screen icon, and a picture that shows when a link is shared. Search engines can now read who makes Gaitro and what each plan costs. The Start free and Log in buttons go straight to the app, without a redirect or an error on every page load, and gaitro.com/pricing/ now goes to the pricing page instead of the app.
- v3
The sidebar now has one Settings link, at the bottom where Docs was; People, Agents and Plan & billing are the tabs inside it. Docs sits under a new Resources section. On People the role controls line up on every row and Remove is red, as are the other buttons that remove or delete something. 'Your agent' is gone from project settings on hosted Gaitro, where it had nothing to set. Tables have a header band, including tables inside documents. The Code tab has a file tree whose folders open and close, in its own scrolling panel, and documents no longer spill out of their card.
- v2
Creating a project, and every publish after it, saved each piece of the code index with its own trip to the database: 3,877 trips for Gaitro's own code, which took almost two minutes. The index now sends only what changed, a few hundred at a time, so the same work is about a dozen trips. gaitro init also says what it is doing while it packs, uploads and fetches, instead of sitting silent.