3.9.0¶
Release Date: September 2, 2026
This release ships the forge and forge-planning skill packages as installable Agent Plugins, bundles the Mosaic MCP server for design-system access, and completes the multi-phase effort to eliminate tfe_outputs remote-state coupling in Terraform modules — with a CI guardrail so it can't regress. The CLI adds plan-mode permission classification for saif commands and Agent Plugin auto-install/update via doctor fix, and Terraform defaults blob storage to private-endpoint isolation.
✨ New Features¶
Agent Plugins & MCP¶
- Ship forge and forge-planning as installable Agent Plugins packages, bundling the Mosaic MCP server in the forge package (
cafa0c53| #1001,25d84b2c| #1040) - cli -
saif agent initregisters and directly installs Forge Agent Plugins, now defaulting to a user-scoped install (c7cc1954| #1012,4f59d668| #987) - cli -
saif doctor fixdetects and updates installed Agent Plugins (f03d7cf0| #1034) - mosaic - bump Mosaic to v18 (
e4f93a53| #976) - mcp - upgrade to MCP 2026-07-28 with explicit conversation IDs (
e0a940ac| #1024)
CLI¶
- Classify
saifcommands as read-only/mutating and generate plan-mode permission rules from the classification (b6189973| #977) - Scope pipeline logs to the job/step in a build URL (
c3677a3d| #1107) - Show installed and latest versions in
doctorresults (2fb00883| #1072) - Add
--trace-idto otel traces and logs (745b21bf| #921)
Terraform¶
- Default blob storage to a private endpoint with network isolation (
c5810602| #1037) - Grant Document Intelligence RBAC via an identity module flag (
b80b35c3| #1047) - Configure the Okta provider from an env-category variable set, and attach the existing Okta variable set to app workspaces via
tfe-bootstrapper(a59e76fc| #845,aeda4776| #1023) - Eliminate the residual
okta_apptfe_outputsread, closing out the #845 migration (6a6b5685) - infra - add app-specific custom domain support to Front Door routes (
f93a7fe3| #929)
Governance & Templates¶
- templates - add PlatformDev as a bootstrap
additional_environmentsentry (832f5043| #1031) - business-roles-corp - warn when
manual_usersis set in non-production (9938d4ad| #1110) - client - add TanStack Query (
16bf191c| #964)
🔧 Enhancements¶
- infra - eliminate all remaining
tfe_outputsremote-state lookups (#845 Phase 1 — zero residuals) (b36c51e4| #914) - cli - retire MCP guided-workflow prompts for shipped skills (
41112865| #1017) - Fix oversized skill descriptions and strip anti-triggers (
20c3bd8c| #1068)
🐛 Bug Fixes¶
CLI¶
- Exclude Smithy's native-duplicate MCP tools from the remote bridge (
ab6fe358| #1013) - Compare remote URLs semantically in
AddRemoteAsync(ffd3f0b4| #961) - Use
-EncodedCommandfor the detached self-update process (69879833| #960) - Emit filter-field syntax in the traces explorer deep link (
683c821f| #955) - Surface failed pipeline steps whose log lives on an ancestor record (
f494e214| #954)
Terraform¶
- Avoid a
depends_oncycle insaif-application-permissions(aebba880| #1080) - Suppress role-assignment scope casing drift, adding
replace_triggered_byhardening to the casing-drift-guarded assignments and covering the remaining KV secret readers (bc0e6387| #1077,0693106a| #1075) - Show available subdomain keys in the custom-subdomain check message (
4289cd30| #1046) - Grant storage Blob Data Contributor to the app registration service principal (
55dd1673| #1027) - Resolve the blob storage connection string from module output instead of a stale reference, and stop passing null network rule args to
storageaccount(e3ec6838| #1005,83e71f49| #1004) - saif-event-service - wrap
fd_custom_domain_idswithnonsensitive()before iterating, and dedupe Front Door custom domain IDs to fix a prod deploy failure (c868898c,3a53ff54| #947) - tfe-bootstrapper-business-roles - stop attaching the Okta corp variable set to corp-tenant workspaces (
05d7bc10| #1108)
Templates¶
- Remove the Okta provider/variables from the corp test-tools scaffold (
5d23e80a| #1111) - Fix frontend pre-commit/pre-push hooks and unit test failures (
1915147e| #1030) - Remove a stray
infra/auth/externalfolder and refresh the blob storage docs (a7a0c9dc| #999)
Workflows & CI¶
- Bump the pinned
Microsoft.Extensions.AIpackage version to resolve a SmithyNU1605restore failure (563750ad| #1097)
Other¶
- oracle - escape Oracle connection strings via
OracleConnectionStringBuilderso passwords containing;no longer corrupt the connection string (07917c0f| #962) - ui - add body-scroll-padding (
132359a6| #956) - git - stop
Directory.Packages.propsshowing as permanently modified, and renormalize its line endings per.gitattributes(bb04dc47| #953,c07ffc64| #935,6f406999)
📚 Documentation¶
Troubleshooting Articles¶
New articles cover: null function_app_service_plan_id (#1109), a tainted-role-assignment guide and preferring the saif CLI for pipeline log triage (#1104), storage account network_rules null errors (#1093), blob storage 403 AuthorizationPermissionMismatch (#1091), saif publish pipeline creation and remote URL issues (#1090), a function app deploy invalid-version warning (#1089), AzureCli Authorizer az not found (#1088), an application_permissions inconsistent final plan (#1086), and system/coding-agent Azure DevOps MCP setup (#1084) — with a companion fix correcting the Azure federated identity setup for the coding agent and code-review OIDC (#1087).
Guides & Reference¶
- platform-typespec - add reference documentation for
@saif/platform-typespec(5aa532c9| #1063) - tutorials - close the local-to-deployed gap in onboarding (
fa7dd92a| #1041) - Add an on-premise API proxy strangler plan and a YARP auth anti-corruption layer one-pager for the Guidewire Cloud migration (
321dde84| #972,a32e7ae9| #915) - Correct the custom subdomains guide for the cloud-foundations flow (
f460ffd0| #959) - auth - document the client-credentials fallback for when no incoming token is present (
44e778a0| #911) - Warn against creating a duplicate business roles repo (
7a4bc425| #1106)
Cleanup¶
- Retire shipped/stale planning docs, distilling durable reference content, and archive the forge-v1-to-v2 migration guide (
bf5e47ab| #990,12217200| #1019) - Remove the stale platform roadmap page and its remaining bullets (
2b8d5556,e3f1067f) - storage-account - hardcode
contributor_group_idinstead of a data source lookup (ca2aa93d| #1009)
📦 Dependencies¶
Routine dependency maintenance via Dependabot: 34 PRs across NuGet and npm/yarn workspaces, including notable manual bumps of @typespec/http-server-csharp, Verify.XunitV3, postcss, fast-uri, and @opentelemetry/auto-instrumentations-web. See the full commit range for the complete list.
🔄 Breaking Changes¶
None in this release ✅
📋 Additional Notes¶
- Total commits: 133
- Files changed: 1156
- Contributors: Brian Sheridan, Copilot, dependabot[bot], Emmitt Johnson, Gabe Higginbotham[C], Jason Coria Corona Yue, jasyue
Support¶
- 📧 Teams Support Channel: Support