Two personal-data ignore rules existed in .gitignore but not in REQUIRED_IGNORE_RULES, so a change weakening either would have passed CI: cover_letters/Cover_*.* (the uppercase naming variant /apply recognizes) and cv/*.txt (ATS text extractions of tailored CVs). Also: regression tests pinning #252's ragged-row bounds fix in convert_salary_excel.py (mutation-verified), and removal of the vestigial cover_letters/OpenFonts/cover.cls, which since #252's rename ambiguously declared the same class as the real cover.cls (zero references; cover letter re-compiled and page-verified after removal). Guard-list gap surfaced by CodeRabbit's review on jakob1379's Nix demo fork PR (jakob1379/ai-job-search#1). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
7.3 KiB
Changelog
All notable changes to this project are documented here. The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
Releases are vetted checkpoints of master. If you maintain a personalized fork,
prefer updating to a tagged release over pulling raw master (see
SETUP.md, section 8). The
framework_version markers on methodology files tell you which of your customized
files a release touched; python3 tools/check_upstream_updates.py lists them with
per-file diff commands.
Unreleased
Security & privacy
- The gitignore guard now covers two more personal-data rules -
security_guards.pyrequirescover_letters/Cover_*.*(the uppercase cover-letter naming variant/applyrecognizes) andcv/*.txt(ATS text extractions of tailored CVs) in.gitignore, so a future change weakening either rule fails CI instead of silently making personal files trackable. Both rules were already present in.gitignore; only the guard lagged.
Fixed
- Removed the vestigial
cover_letters/OpenFonts/cover.cls- an unreferenced remnant of the original font bundle that, since #252's class rename, ambiguously declared the samecoverclass as the realcover_letters/cover.cls. - Added regression tests pinning #252's ragged-row bounds fix in
tools/convert_salary_excel.py(dimension-less workbooks read inread_onlymode yield rows shorter than the header).
[1.1.0] - 2026-07-30
Security & privacy
- Personalized custom-template files are now gitignored regardless of engine - the
ignore rules broadened from
cv/main_*.textocv/main_*.*(and likewise for cover letters), so a fork using a Typst or other non-LaTeX template no longer commits personalizedmain_<company>.typfiles to a public fork. The*_example.texfiles stay tracked. If you registered a custom template before this release, checkgit statusonce after updating. (#238) - Dependency review is live, for forks too - the repo's Dependency graph is now enabled,
so the CI
dependency-reviewjob actually blocks PRs that introduce dependencies with known high-severity vulnerabilities, and the job is no longer gated to the upstream repo: forks get the same check, self-activating if the fork enables Dependency graph (it warns-and-passes otherwise). (#254)
Added
- freehire-search: full descriptions come back with the search -
searchnow calls freehire's agent search endpoint (/api/v1/agent/jobs/search), which serves each hit's complete description instead of the search index's truncated preview. A 20-role search is one request rather than 1 + 20detailcalls, and/scrape's Step 2 no longer needs a per-hit fetch for this portal.--description-format markdown|text|html(defaultmarkdown) selects the rendering;tableandplainoutput is unchanged. (#251) - Custom templates: any compile-to-PDF toolchain (Typst, ...) -
/add-templateno longer hardcodes alualatex/xelatex/pdflatexengine enum. Custom templates now declare a source extension and a full compile command, so Typst (typst compile) registers the same way a custom LaTeX template does. Stock CV/cover letter templates stay LaTeX, unchanged. (#238) - Application-form fields as an optional third
/applyartifact - when a posting's application form asks screening questions,/applycan now offer a prep sheet of grounded answers alongside the CV and cover letter. Opt-in; the default two-document output never changes. (#212) - Confirmed facts write back to the profile - when
/applyor/interviewsurfaces a fact the user confirms (a skill, a date, a project detail), it is written back to the profile files in the same turn instead of being lost with the conversation. (#211) - CV methodology: in-progress qualifications and tenure-vs-output -
05-cv-templates.mdgains explicit rules for stating in-progress certifications/degrees honestly and for checking claimed tenure against visible output (framework_version1.2.1 -> 1.3.0). (#210) - Scraper flags mass-posting and recycled-listing patterns -
/scrapemarks postings that look bulk-posted or recycled so they don't eat evaluation effort. (#207) - Retry contract pinned in CI - all six portal CLIs now carry 429/5xx retry-backoff tests covering every fetch wrapper, so a silent regression in retry behavior trips CI. (#246)
- README: the extension model, documented - new Customization subsection "Extending the framework: portals, templates, criteria - and borrowing from other forks": the three extension points, the copy-one-folder pattern for borrowing a portal skill from another fork with a read-the-code-first checklist, and why there is deliberately no installer (the manual copy is the security model). Prompted by discussion #249.
Fixed
/rankshortlist and below-threshold tables include each posting's URL. (#236)convert_salary_excel.py: count/index columns pair by category name instead of adjacency (#219), standalone count columns store as counts (#230), and ragged rows from dimension-less spreadsheets no longer crash with an IndexError (#252).cover.cls: duplicate package imports removed and the\ProvidesClassname fixed to match the filename, silencing a class-name-mismatch warning. (#252)- Portal CLI type-checking pinned to concrete
@types/bun/@bunli/*versions to stop environmental CI type-drift. (#226) freehire-searchpoints at freehire.me after the service's domain migration. (#229)verify_pdf.py's missing-poppler error now includes per-OS install hints. (#252)
1.0.0 - 2026-07-22
First tagged release. This marks the framework as stable and gives forks a described
checkpoint to update against instead of a moving master. It is a baseline of what
already exists rather than a set of new changes; subsequent releases will document
what changed since the previous tag.
At this baseline the framework provides:
- Application workflow - a drafter/reviewer
/applypipeline (CV + cover letter), plus/setup,/scrape,/rank,/interview,/outcome,/upskill,/expand,/html-report,/gmail-sync,/notion-sync,/add-portal,/add-template, and/reset. - Portal search skills - country-agnostic job-board CLIs (LinkedIn, freehire, and
the Danish boards) in the portable Agent Skills format under
.agents/skills/, discovered and orchestrated by/scrape, with anenabled:toggle for skipping portals. - Framework versioning -
framework_versionmarkers on methodology files plustools/check_framework_version.py(CI guard) andtools/check_upstream_updates.py(fork-side update preview). - Privacy and safety guards -
.gitignoreprotection for personal data, thetools/security_guards.pyallowlist for.gitignorenegations, and a CI policy of making no live portal requests. - Cross-runtime support - a root
AGENTS.mdpointer so Codex and Antigravity can discover the portable portal skills, with Claude Code as the reference runtime.