Product
Changelog
What shipped, in the order it shipped. Only released capability appears here — nothing on this page is roadmap. Get these by email from the waitlist.
October 3, 2026
The legal pages now name the entity that exists, and the forum its licence implies. The contracting party on the Terms, the Privacy Policy and the DPA is Winch Labs FZ-LLC — one word — the company licensed in the in5 / Dubai Development Authority free zone and issued on 29 September 2026. The earlier spelling named nothing. Governing law and forum moved with it: the federal law of the United Arab Emirates as applied in the Emirate of Dubai, with disputes to the Dubai Courts, replacing the DIFC. A DDA free-zone entity has no court of its own — unlike the DIFC or ADGM, which are opt-in common-law jurisdictions — so this is the forum the licence already implied rather than an election we made, and it is the same wording the design-partner and government agreements now carry. Nothing about the processing moved: the sub-processor list, the 48-hour breach notice, the eu-central-1 residency and the retention and deletion windows are byte-identical. All three documents are now v1.1, dated 3 October 2026. One distinction worth stating plainly, because it is not a rename: Winch Labs remains the brand and the wordmark, and Winch Labs FZ-LLC is the legal person that signs. Under §16 of the Terms this entry is that announcement, and the 14-day notice period runs from today.
September 6, 2026
The composite gap is closed, and the benchmark line is 40 repos · 56 findings · 28/40 silent · 61→239 conventions · 0 parse failures. Later the same day as the rebaseline below, garboard v0.1.65 shipped the product decision the attribution had surfaced: the XRD decides what its composite resource is. A family that declares claimNames keeps the August 30 behaviour — its composite is what a claim resolves to, and it runs through no claim rule; so does any composite carrying a crossplane.io/claim-* backref or a spec.claimRef, because a backref only exists on a derived object. A family that declares none — a Crossplane v2 XRD, or a v1 XRD that never offered claims — has no claim at all, so its composite is the object a platform user authors by hand, and it is now gated as the claim-shaped unit it is; findings say "Composite resource" where they used to say "Claim" and are otherwise byte-identical. On the corpus that re-admits the 22 true Warn-level findings on the three Upbound repos (configuration-aws-database 5 → 17, configuration-aws-network 0 → 5, platform-ref-aws 0 → 5) and the two crossplane.namespace conventions derived from them, 237 → 239; the plaintext_secret false positive stays gone, and every other repo's numbers are identical. That is re-admitted coverage, not noise added — net against the 54 that stood before August 30, +2: three true positives on a vendored CloudFormation template, one false positive fixed. Silent repos 30 → 28. The attribution →
September 6, 2026
The benchmark, rebaselined: 40 repos · 34 findings · 30/40 silent · 61→237 conventions · 0 parse failures. The count had read 54 since August 18. Two gate changes on August 30 moved it to 34, and neither measured the corpus when it landed — so we attributed the step commit by commit, rebuilding one binary per candidate and re-gating the four repos whose counts changed. −23: Crossplane composite resources are no longer gated as claims, and every finding on the three Upbound repos' hand-authored examples/*-xr.yaml files left at once — 22 true Warn-level convention findings and one plaintext_secret that was a false positive. That is a coverage gap, published as a gap and not as noise removed: in a Crossplane v2 repo the composite is the hand-authored object, and the gate currently says nothing about it. +3: a vendored CloudFormation template in 18F/identity-terraform became visible to the new frontend — three unencrypted buckets. Silent repos 29 → 30; conventions 239 → 237. The earlier 622 → 54 stays what it was, false-positive tuning on the original 30 repos, and is never summed with this step. The attribution →
September 3, 2026
Blast radius now crosses repository boundaries. A change to a shared module used to say what it reached inside its own repository and stop there. Deltz now adds a second line to the same note — "consumed by 3 repos across 2 envs (prod: 2)" — naming the other repositories in your organisation that consume the module you just moved, which of them track this branch, which are pinned and pick it up only on a deliberate upgrade, and which sit on a different branch that nothing but a backport reaches. The edges are derived at scan time from each repository's own module sources, so a review still spends one indexed read; refs are read by shape and never resolved against the host. The limits are stated in the sentence itself rather than in a footnote: only repositories this organisation has scanned are counted, so the figure is always a lower bound, and the line carries the age of the oldest scan behind it. Nothing about blocking moves — merge checks still read the in-repo score alone. A new Module graph screen shows the whole estate, names every repository that has not been derived yet, and lists the module sources it could not read, grouped by why. How to read every clause.
September 2, 2026
Fixes arrive as suggested changes you choose to apply. A gate-passing fix no longer lands on your branch as a commit you did not ask for. Deltz now posts it on the pull request as the host's own suggested-change blocks — on GitHub and GitLab alike — anchored to the exact lines, one block per place the fix touches, with the rationale above the first. You read the diff inline, apply the blocks you want or ignore them, and the choice of what to commit stays yours. The gate does not move: only a fix that already passed the re-gate is ever posted, and applying a block is a push, which is reviewed again like any other. When a fix cannot be expressed as blocks — the hunk lies on a line the diff does not show, or the branch moved mid-draft — the note says so and offers the same gated file as a single commit; organisations that prefer commits first can say so with one policy key. Fix links now resolve on GitLab too.
September 1, 2026
GitLab, live. Deltz now reviews merge requests on a live GitLab project end to end — webhook in, gate verdict, note posted, evidence links resolving into the project at the reviewed commit. Each organisation connects its own GitLab — gitlab.com or a self-managed instance — with its own credentials, sealed under envelope encryption like every other secret we hold. Reviews and evidence are host-aware, so links always point at your GitLab, never a lookalike. The GitLab path is younger than the GitHub one; what remains unproven is named plainly in the docs rather than left for you to find.
September 1, 2026
Pulumi changes, reviewed through preview artifacts. gate --pulumi-preview accepts the JSON your own CI produces with pulumi preview --json — the fourth artifact input, beside Terraform plans, rendered Crossplane output and CloudFormation change sets. Because a preview is post-evaluation truth, the gate checks resolved property values and flags destroys and replacements of stateful resources against the same curated tables the HCL path uses. The boundary, stated plainly: Deltz does not parse Pulumi programs or derive conventions from them — your CI runs the credentialed step, Deltz only ever sees the file. No credentials, no state files.
August 31, 2026
CloudFormation and SAM templates, through the same gate. Deltz now parses CloudFormation and SAM templates — YAML and JSON — into the same facts model as HCL, so the built-in rule table transfers instead of being rewritten: a publicly accessible or unencrypted AWS::RDS::DBInstance draws the same evidenced finding as its Terraform twin, on pull requests and in offline CI alike. Intrinsics (!Ref, !Sub, Fn::If) follow the house discipline — unknown values are never guessed at, so a parameterised template under-reports rather than false-positives. Under the hood this rode in on a real seam: one frontend registry now routes every framework, which also fixed a long-standing split where a mixed Terraform + Crossplane repository derived different conventions from a scan than from a webhook. Not every rule maps yet — the mapped set carries the same CIS/SOC 2 control tags as its HCL counterparts, and the unmapped remainder stays honestly unmapped.
August 31, 2026
Waivers that scope, rules that soak. A break-glass override can now be scoped to a single rule instead of neutralising the whole review, and newly adopted library rules can start in a shadow state — evaluated and recorded on every PR, visible to admins, invisible to authors — so a rule earns its way to advisory and then blocking with evidence, not hope. Muted findings are recorded rather than silently discarded, which makes "what did our suppressions hide this quarter" an answerable question for the first time.
August 30, 2026
-
Cost on every pull request, and budgets that hold.
Every reviewed change now carries its estimated monthly cost delta — base to head, from an embedded, locked pricing table; anything variable-driven stays honestly unpriced rather than guessed. Organisations set a budget policy per environment ("prod delta over $150 needs a decision"), breaches arrive as an evidenced finding on the PR, and a fleet-wide Cost view totals the month's reviewed changes. Uncounted reviews say so, in so many words.
-
Signed receipts: the audit trail becomes cryptographic.
Every review and merge now writes a hash-chained receipt — what was checked, what was found, who approved — verifiable in the product and exportable as an evidence bundle for a chosen period. New receipts are ed25519-signed, with the public key served at a well-known URL so verification never needs Deltz's word for it.
-
Blast radius, destructive changes, and who — or what — wrote the change.
Reviews of shared modules now show their blast radius: which units consume the changed code, across which environments, weighted so production counts most — context beside the verdict, never a gate of its own. A destructive-change family catches the quiet killers: renames and immutable-field edits that force destroy-and-recreate, flagged at PR time from HCL semantics and a curated per-provider table, no plan required. And every review records authorship provenance — human, AI-assisted, or AI-authored, detected deterministically from trailers and identities — filterable across the fleet, with per-tier policies (require human approval, disable auto-fix) available per organisation.
-
A rule library you adopt, not inherit.
A curated catalog of ~112 rules mapped from Checkov, tflint and tfsec (Apache-2.0, attributed) ships inside the binary — browseable with deterministic, explained recommendations ranked against what your repos already do. Nothing enforces until a human adopts it; adopted rules then run inside the same gate as every built-in, org-wide or per repository, with curated profiles for one-click baselines. Offline CI gets the same catalog via
gate --profile. -
Per-organisation SSO.
Customers connect their own OIDC identity provider from Settings: verified domains with DNS TXT ownership proof, email-first sign-in that routes each person to their workspace's provider, an enforce-SSO switch with an owner break-glass path, and client secrets sealed with envelope encryption. Hardened against the obvious abuses — domain hijack attempts, cross-org token substitution — with the test suite to show for it.
August 26, 2026
GitLab support, and memory that knows what got rolled back. Deltz now speaks GitLab as well as GitHub — merge requests, notes, commit statuses and webhook verification, behind the same provider seam, so the review pipeline itself is unchanged. (Code-complete and tested against recorded fixtures; not yet run against a live GitLab project.) Episodic recall gained a real embedding backend for hosted installs and a deterministic offline reranker, and it now down-weights episodes whose change was later reverted — a rolled-back pattern is still evidence, but it should never be the one you copy. Self-hosting gained a Helm chart: one chart, the binary plus Postgres, every credential by reference rather than a plain value.
August 26, 2026
Audit exports, compliance tags, and read-only API tokens. Admins can now export the audit log as CSV over any time range — the access-review artifact enterprise buyers ask for — and self-hosted installs can opt into a retention window (unset means keep forever; a sweep records what it removed in the org's own trail). Gate findings now carry CIS AWS Foundations and SOC 2 control tags in SARIF and JSON output, mapped conservatively: rules with no defensible mapping stay untagged rather than stretched. API tokens are read-only and rate-limited — a leaked CI token can read, never mutate.
August 26, 2026
Convention documents now keep their history. Every derivation is retained, so a repository's context screen can show what actually changed since the previous version instead of only the current state — added, changed, decayed and removed conventions, with the old pattern shown against the new. Re-scans stream their real progress live (clone → parse → derive → render) rather than sitting silent until they finish. Terragrunt dependency blocks are parsed into unit facts and surfaced as a convention.
August 25, 2026
The benchmark corpus grew from 30 repositories to 40 — and the finding count did not move. Ten more real repositories (Azure and GCP official modules, a 111-file GCP tree, a 99-file AWS IAM module, three more Terragrunt trees) produced zero new findings while contributing 56 new conventions. Now: 54 findings · 237 conventions · 29/40 repos silent · 0 parse failures. Silence was verified rather than assumed — adding one bad file to a corpus repo immediately yields four findings. Full writeup →
August 25, 2026
A third false-positive class, found and fixed. Upbound package manifests (meta.* API groups) were classified as managed resources and drew label findings on their own metadata — 12 false positives across the benchmark's three Upbound repos, gone. The CLI garboard scan now derives Crossplane conventions exactly like the server does, and the benchmark corpus is pinned to exact commit SHAs. Gauntlet at the time: 54 findings · 181 conventions · 19/30 repos silent · 0 parse failures. Details →
August 25, 2026
Versioned, advisory-locked database migrations replace startup DDL — self-hosted upgrades are now a restart, with schema changes applied exactly once even across concurrent instances.
August 24, 2026
Seats and invitations. Admins invite teammates by email; an invite grants a seat, never an identity — existing accounts still authenticate with their own credentials. The GitHub App now installs on any org. Installations that arrive outside the app's setup flow appear in Settings as claimable, so connecting an organization is order-independent. Also: a redesigned navigation (regrouped sidebar, collapsible rail, ⌘K command palette) and full mobile support across the app.
August 23, 2026
Hosted early access is live. Sign-in via invitation or single sign-on (any OIDC identity provider), self-service signup stays closed while we onboard design partners. Releases now flow through a tag-to-deploy pipeline with no long-lived cloud keys in CI.
August 18, 2026
Crossplane correctness pass: repo XRD groups and claim-shaped documents are never misclassified as standalone managed resources, and Forge authors claims only — platform definitions stay human-owned.
August 11, 2026
Authentication hardening: OIDC nonce verification and email_verified enforcement, sign-in throttling, and anti-enumeration responses across the auth surface.
August 7, 2026
Crossplane EnvironmentConfig support and first-class Terragrunt: templated sources are parsed natively, so Terragrunt units contribute facts and conventions like any other module.
August 2026 — the 30-repo gauntlet
We ran the gate over 30 public Terraform/OpenTofu repositories as a standing benchmark: two false-positive fixes took total findings from 622 to 54 across the corpus, convention derivation grew from 61 to 178 learned conventions, and the parser finished with 0 failures. This corpus now gates releases. Full writeup →
August 1, 2026
Four-tier pricing: free Starter on your own Claude API key; Individual and Team include Claude usage on our keys; SSO ships with Team. The deterministic gate needs no key on any plan.
July 30, 2026
Multi-tenant SaaS foundation. Organization isolation enforced at the database layer, role-based access control, per-org convention overrides, and OIDC single sign-on.
July 3, 2026
Crossplane fix support: YAML fixes are drafted and re-checked by the same gate that reviews external PRs — generated output is never exempt from review.
June 24, 2026
Deltz v0.2. Review, fix and episode memory shipped together with Forge (gated generation) and the MCP server — coding agents can pull a repo's conventions and self-check a diff before a PR exists. Docs →
Follow along — new entries land here first. Subscribe on the homepage →