Every release, grouped by what changed. Generated from commit history.
Upgrading? Read UPGRADING.md first. This file lists what changed; that one lists what you have to do. They are not the same, and this file cannot be trusted to flag breaking changes — only one commit in the project's history carries a breaking-change marker.
Releases before 1.0.0 were recorded by hand and are kept verbatim in
docs/changelog-0.x-handwritten.md.
- Generate CHANGELOG.md from the ~200 releases that already happened
- Explain GPU passthrough, and pin that it stays optional (#248)
- The quickstart no longer contradicts the security page (#246)
- One configuration reference, and it states which source wins (#245)
- Workers report disk and GPU, and say when they cannot tell (#247)
- Add UPGRADING.md, and pin the compose examples to 1.12 (#243)
- A container ID never overwrites a worker's real name (#244)
- The heartbeat response carries what the worker's platforms earned (#242)
- Stop publishing agent working files on the public docs site (#241)
- The claim modal said "Service not found" about services that exist (#240)
- Show the version the app is actually running (#239)
- The two container inventories no longer disagree (#238)
- Three ways the fleet page misled the person reading it (#237)
- Stop asserting a zero nobody measured, and say why Settings is empty (#236)
- Make five guards report what they actually checked (#234)
- Unknown watts must suppress the net, not price it at zero (#235)
- Bound the window in which the shared key still works for a worker (#233)
- Collect credentials that were stored before saving them began tracking (#232)
- Exchange-rate staleness was computed, published, and read by nobody (#231)
- A fresh install and an upgraded one had different config schemas (#230)
- One ERROR per request when /fleet is not writable (#229)
- The lockout alarm skipped the lockout it was most needed for (#228)
- Two affirmatives nobody had earned (#227)
- A container nobody could measure reported 0.00% CPU (#226)
- The release was announced before the images existed (#225)
- Ticking two nodes behind one connection warned about nothing (#224)
- The wizard's expected end state was a dashboard reading zero (#223)
- The LAN-isolation warning named the wrong service, twice (#222)
- A worker named "toString" was never flagged as a duplicate (#221)
- Two worker rows, one name, and no way to tell them apart (#220)
- The running-costs feature had no way to configure it (#219)
- Neither image knew what version it was, so skew was undetectable (#218)
- The header plane was white and the wordmark was not the brand pink (#217)
- The test suite ran against a resolution nothing else used (#216)
- Two more route sweeps were quietly shrinking on Starlette 1.3 (#215)
- The fleet-offline recovery message named the wrong variable (#214)
- A service was called idle before it had a chance to earn (#213)
- A container you started yourself got live buttons that 404 (#212)
- The credential checker was correct, complete, and had no caller (#211)
- A worker that cannot read Docker fabricated downtime for every service (#210)
- A correct balance was thrown away and reported as a collector failure (#209)
- The one credential needing a shell command had no hint on screen (#208)
- Three catalog entries stated their payout minimum in two units (#207)
- Every wizard-deployed host registered as "cashpilot-{hostname}" (#206)
- Flatline alerts reached the database, the notifier, and nobody else (#205)
- An upgraded install kept its provider credentials in plaintext forever (#204)
- The release workflow could not pass its own test suite (#203)
- The dashboard asserted $0.00 before anything had ever looked (#202)
- An unreachable host reported its containers as running (#201)
- A dollar balance was compared against a token minimum at 1:1 (#200)
- Fleet running costs subtracted a EUR tariff from a USD gross (#199)
- Removing a worker no longer locks the host out permanently (#197)
- Net earnings subtracted a EUR cost from a USD gross (beads batch 13) (#196)
- An undocumented payout minimum is not zero, and settings that never applied (beads batch 12) (#195)
- The quickstart installed 1.4 (issue #188), and bump cryptography past a CVE (#194)
- A wizard that congratulated failed deploys, and a modal missing its own recommendation (beads batch 11) (#193)
- Prove the auth guard for every route instead of 14 hand-listed handlers (#198)
- Preflight now applies the schema's documented vps_ip default (#192)
- Two guards that could not fail, and one bead corrected (#191)
- An unreachable machine is not a machine earning nothing (beads batch 8) (#190)
- Releases that publish nothing, and docs naming the wrong encryption key (beads batch 7) (#189)
- Credentials alone now collect, and the collection test can fail (beads batch 6) (#187)
- Make payouts visible — a queue to answer them, and progress toward the next one (#181)
- Record the v1.10.0 terminal state [skip ci]
- Correct money, access-control and recovery defects found auditing v1.10.0
- Own the attribution risk, and contain the lateral one (CashPilot-q0o) (#174) [skip ci]
- Is this machine worth keeping powered on? (CashPilot-l01) (#173) [skip ci]
- Optional container runtime, explicitly unsupported (CashPilot-54q) (#175) [skip ci]
- Payouts, lifetime-vs-balance, and how far off the cashout is (CashPilot-1og) (#171) [skip ci]
- Drop unsafe-inline from the CSP (CashPilot-guw) (#176) [skip ci]
- Generate the README service tables from the catalog (CashPilot-9q1) (#172) [skip ci]
- Encrypted export of irreplaceable service state (CashPilot-qqo) (#170) [skip ci]
- Notice when a provider changes its API, and test credentials on demand (CashPilot-bfl) (#169) [skip ci]
- Is anything actually crossing the wire? (CashPilot-t6y) (#168) [skip ci]
- Componentize the duplicated app.js markup builders (CashPilot-cyc) (#179)
- Break the main -> routers -> main import cycle (CashPilot-sux) (#177) [skip ci]
- Record only per-IP limits a provider actually states (CashPilot-4qv) (#167)
- See the fleet the way providers do — by IP, not by machine (CashPilot-5qc) (#166)
- Per-service disclosure — what it does with your machine (CashPilot-66x) (#165)
- Producer state — is it earning, not just running (CashPilot-b4e)
- Publish both images on every release, and fail if a tag is missing (CashPilot-0zw)
- Clear the outstanding CodeRabbit findings on merged PRs
- Report net profit, not just gross earnings (CashPilot-f5u)
- Charge power per worker, not once for the whole fleet (CashPilot-yh5)
- State the security defaults and enforce them in tests (CashPilot-964)
- Match the site theme to the product it documents
- Let the catalog declare a device, fixing Mysterium's missing TUN (CashPilot-6rv)
- Stop the flatline check crying wolf, and clear it on recovery
- Bump the github-actions group with 4 updates (#144)
- Document the TUN device failure that looks like a healthy node
- Render the feature icons and redraw the header logo
- Record what CashPilot will never do (CashPilot-kct)
- Replace the competitor matrix with a comparison that stays true (CashPilot-qkc)
- Add a direction and roadmap page (#140)
- Detect services that are running but no longer earning (CashPilot-kbs)
- Persist the deployed spec and redeploy from it (CashPilot-tkd)
- Tell the user when a credential is about to expire (CashPilot-aug)
- Pre-deploy reality check (CashPilot-w58)
- Refuse deletes that would destroy irreplaceable state (CashPilot-efx)
- Detect release changes since the last tag, not the last commit
- Pin the example compose files to major.minor, not :latest (CashPilot-jz3)
- Stop logging raw worker error bodies, and 3 review follow-ups
- Clamp earnings per platform so a payout can't erase real earnings (CashPilot-glc)
- Stop silently destroying stored credentials (CashPilot-1ii)
- Offer the durable cookies, not just the 2-hour one (#139)
- Add language identifiers to the log-output code fences (#137)
- Record what actually resisted the container hardening (#136)
- Record the live-fleet hazards that look fine from outside (#135)
- Read the balance from the metric card, not a heading level (#138)
- Do not use an ephemeral container ID as the worker identity (#134)
- Stop reporting a session-capture referral link as dead (#133)
- Add proxybase.xyz service definition (#126)
- Persist collector alerts and deliver them out-of-band (CashPilot-1ty) (#132)
- Weekly catalog liveness check with referral-link guard (CashPilot-owv) (#131)
- Record the FX rate with each earnings reading (CashPilot-rrr) (#130)
- Drop all capabilities + no-new-privileges on deployed containers (CashPilot-a5p) (#129)
- Let operators opt specific volume roots past the block (CashPilot-52w) (#128)
- Update mkdocs-material requirement from >=9.7.6 to >=9.7.7 (#125)
- Refuse deploying broken/dropped services, not just dead (CashPilot-rp3) (#127)
- Extract shared action-button icon constants (CashPilot-cyc) (#124)
- Batch health-check writes, PRAGMA synchronous=NORMAL, concurrent exchange fetch (CashPilot-perf) (#123)
- HSTS + CSP hardening directives + session cookie Secure behind a trusted proxy (CashPilot-sec) (#122)
- Extract SSRF worker-URL validation into app/worker_proxy.py (CashPilot-sux) (#121)
- Unify the two deploy flows so the detail view validates + surfaces errors (CashPilot-cyc) (#120)
- Api_worker_command earnings bug + main.py de-duplication (CashPilot-1k5) (#119)
- Give each worker a stable client_id instead of its mutable hostname (CashPilot-ng1) (#118)
- Detect deployed-image vs catalog-image drift and warn (CashPilot-5wi) (#117)
- Install docker SDK so CI runs the full suite (fix red main from cm6 floor) (#115)
- Stricter loader validation to catch malformed entries (CashPilot-keb) (#116)
- Harden security-path coverage + fix weak/flaky tests (CashPilot-cm6) (#114)
- Bcrypt off the event loop, earnings(date) index, bounded metrics cardinality (CashPilot-apm) (#113)
- Pin third-party actions to SHAs, add HEALTHCHECKs, sync worker Docker Hub desc (CashPilot-7br) (#112)
- Remove verified dead code (CashPilot-4s2, partial) (#110)
- Optional /metrics bearer token + atomic first-owner creation (CashPilot-2zx) (#109)
- Pin validated worker IP to close SSRF DNS-rebinding TOCTOU (CashPilot-drz) (#111)
- Bind UI + Docker-socket worker to loopback by default (CashPilot-jia) (#107)
- Durably revoke sessions on user delete/demote (survives restart) (#106)
- Security + reliability + docs: whole-repo audit follow-ups (#105)
- Update tzdata requirement from >=2026.2 to >=2026.3 (#102)
- Migrate to GHCR peer-cli image + Access Token credentials (#103) (#104)
- Per-worker fleet keys (full cutover, v1.0.0) (#101)
- Deferred audit follow-ups (health growth, first-run token, orchestrator coverage) (#100)
- Code-audit findings — container escape, event-loop stalls, authz, error surfacing (#98)
- Unstable health badge + /metrics exposure warning (#97)
- Raise bitping mem_limit 128m->192m to prevent OOM (#96)
- Bump the github-actions group with 2 updates (#94)
- Use GitHub-hosted ubuntu-latest runners (#93)
- Durable per-service Docker resource limits (#95)
- Block fork PRs from running on the self-hosted runner (#92)
- Bump starlette from 1.0.1 to 1.3.1 (#91)
- Bump cryptography from 48.0.0 to 48.0.1 (#90)
- Bump python-multipart from 0.0.29 to 0.0.31 (#89)
- Build multi-arch images via QEMU on the X64 runner (#86)
- Clearer earnings-tracking state on the dashboard (#82 follow-up) (#88)
- Make docker compose pull/up the correct update path (#84) (#87)
- Codebase audit — bugs, dead code, hardening, test gaps (#85)
- Bump the github-actions group with 9 updates (#81)
- Allow github-actions major bumps (#80)
- Bump deprecated GitHub Actions to current majors (#79)
- Repocket container env should be RP_EMAIL + RP_API_KEY (#82) (#83)
- Remove AGENTS.md (migrated to CLAUDE.md)
- Merge AGENTS.md into CLAUDE.md
- Add CLAUDE.md
- Add CashPilot-Desktop to ecosystem table
- Redesign onboarding as standalone synthwave page (#78)
- Add Anyone Protocol collector and fix CI worker manifest (#77)
- Auto-purge workers offline > 1 hour from fleet page (#76)
- Update Earn.fm tests for Supabase auth constructor (#73)
- Earn.fm collector (Supabase auth), exchange rates, and CSP (#72)
- Format earnfm.py (trailing newline) (#75)
- Trigger release build after test fix (#74)
- Bytelixir collector incorrectly rejects authenticated dashboard at / (#71)
- Sanitize credential values on save and improve Bytelixir hints (#70)
- Chart and inline colors respect theme (light mode readability) (#69)
- Use python -m uvicorn in Docker CMD (shebang path mismatch) (#68)
- Add version input to build dispatch, pin compose to v0.6.2 (#67)
- Release workflow skip compose pin push (branch protection) (#66)
- Rebuild worker on catalog changes, improve credential UX (#64)
- EarnFM token auth, Prometheus metrics, orchestrator resilience (#62)
- Pin Docker images to v0.5.1 instead of latest
- Pin Docker images to v0.5.1 instead of latest
- Convert Docker build to native split-build (amd64+arm64)
- Drop privileged from all services, rewrite earnfm to token auth (#61)
- Update pytest-cov requirement from >=5.0 to >=7.1.0 (#55)
- Update ruff requirement from >=0.11.0 to >=0.15.13 (#53)
- Update pytest requirement from >=8.0 to >=9.0.3 (#51)
- Security hardening, collector refactor, and API conformance (#57)
- Update uvicorn requirement from >=0.46.0 to >=0.47.0 (#52)
- Update python-multipart requirement from >=0.0.28 to >=0.0.29 (#50)
- Update pytest-asyncio requirement from >=0.23 to >=1.3.0 (#56)
- Update tzdata requirement from >=2024.1 to >=2026.2 (#54)
- Container crash when started with --user flag (Unraid) (#49)
- Reject deploy of dead services and gate release on CI (#47)
- Ecosystem audit — auth hardening, compose fixes, fleet docs, XSS, validation (#46)
- Correct Presearch env var name to REGISTRATION_CODE (#45)
- Update python-multipart requirement from >=0.0.27 to >=0.0.28 (#43)
- Update httpx requirement from >=0.28 to >=0.28.1 (#39)
- Update fastapi requirement from >=0.115 to >=0.136.1 (#40)
- Update apscheduler requirement from >=3.10 to >=3.11.2 (#41)
- Update mkdocs-material requirement from >=9.5 to >=9.7.6 (#42)
- Update jinja2 requirement from >=3.1 to >=3.1.6 (#37)
- Update aiosqlite requirement from >=0.20 to >=0.22.1 (#36)
- Update uvicorn requirement from >=0.34 to >=0.46.0 (#34)
- Update cryptography requirement from >=44.0 to >=47.0.0 (#33)
- Update pyyaml requirement from >=6.0 to >=6.0.3 (#35)
- Update docker requirement from >=7.0 to >=7.1.0 (#32)
- Update uvloop requirement from >=0.21 to >=0.22.1 (#31)
- Update bcrypt requirement from >=4.0 to >=5.0.0 (#30)
- Switch to self-hosted runner
- Switch to self-hosted runner
- Switch to self-hosted runner
- Switch to self-hosted runner
- Switch to self-hosted runner
- Switch to self-hosted runner
- Switch to self-hosted runner
- Switch to self-hosted runner
- Update python-multipart requirement from >=0.0.18 to >=0.0.27 (#29)
- Add Codecov badge to README (#28)
- Add social preview image (1280x640 Open Graph)
- Add setup-python to CodeQL for self-hosted runner (#26)
- Improve test coverage to 90%+ (#27)
- Update Storj deployment and add stop_timeout support (#25)
- Add option to clear service credentials (#23)
- Add .ghost-portfolio.yml for portfolio page
- Update proxyrack.yml to match min. payout. (#21)
- Add missing fleet_key.py to worker Docker image (#20)
- Use
UTCimport instead ofdatetime.UTCattribute (#18)
- Suppress stack trace exposure in worker status page (#17)
- Drop passlib + security hardening — fixes #15 (#16)
- Add stale issues workflow
- Truncate password by UTF-8 bytes, not characters (closes #15)
- Format test_summary_bonus.py
- Signup bonus offset — subtract promotional credits from balances
- 4 review findings — encryption, auth, storj tests, traffmon heuristic
- MystNodes auto-settle cashout, rewards link, claim modal
- Correct cashout URLs and min payout amounts
- Traffmonetizer requires browser JWT (reCAPTCHA blocks login)
- Traffmonetizer uses email/password, not Docker token
- Update PacketStream scraper for new dashboard HTML
- Green toast after credential save, silent dashboard refresh
- Remove all optional collector fields, add hints for every service
- Credential modal alignment, hide optional fields, add hints
- Inline credential update from dashboard and notifications
- Add growth strategy playbook
- Support Android apps in worker heartbeat and UI
- Add CodeRabbit configuration
- Label Android TX/RX in dashboard sub-rows
- Recreate idx_workers_status after migration, minor cleanups
- Use stable client_id for worker identity, add worker tests
- Address review findings on Android worker support
- Center sun in favicon, icon, and logo SVGs
- Update to tailored CodeRabbit config
- Update bcrypt requirement from <4.1,>=4.0 to >=4.0,<5.1
- Add cross-references to related projects
- Update all icons and banner to new airplane logo
- Update roadmap with all built features
- Add v1.5 Multi-Platform Agents to roadmap
- Add Salad earnings collector
- Add related projects section
- Auto-create external deployment for manual-only collectors
- Salad uses auth cookie + XSRF double-submit, not Bearer
- Salad API moved to app-api.salad.com with Bearer auth
- Comprehensive audit and hardening (v0.2.49)
- Use CSS grid for collector credentials to prevent overflow
- Use fence_code_format for mermaid (fence_mermaid removed in pymdownx 10+)
- Add app icon for Unraid CA template
- Add credential fields for bytelixir/grass, setup guide links in wizard
- Support Bearer API key auth on all API endpoints
- Add Setup Guide links to service detail views
- Add repo polish: tests, templates, docs site, Unraid templates, comparison table
- Add Docker Hub README sync workflow
- Remove draft posts from repo
- Fix Titan Network dashboard URL to edge.titannet.io
- Fix dashboard URLs for Titan Network and Uprock
- Remove GRASS from crypto-to-USD conversion
- Fix Grass and Bytelixir collectors to return real earnings
- Use remember_web + XSRF cookies for persistent auth
- Add startup collection trigger and Grass 429 retry logic
- Fix real earnings for Grass/Bytelixir, fix collector grid layout
- Show credentials with eye toggle, dashboard links for deployed services
- Fix collector grid: prevent row height sync when details expand
- Show actual defaults for all env vars, add Default badge
- Add show/hide toggle for secret env vars (Fleet API Key, etc)
- Remove fake DATABASE_PATH env var, show defaults for all env vars
- Remove General settings, add HOSTNAME_PREFIX + COLLECT_INTERVAL env vars
- Fix ruff formatting in env-info endpoint
- Redesign settings: dynamic env vars, all 13 collectors, fix saveSettings bug
- Fix worker action/logs API paths: /api/containers → /api/services
- UI overhaul: worker-aware deploy, per-worker management, catalog fixes
- Pin bcrypt<4.1 to fix passlib initialization crash
- Fix bcrypt 72-byte password limit on Python 3.14
- Fix wizard deployed badges, node count, signup buttons, and Mysterium port forwarding
- Add port forwarding requirement to Anyone Protocol guide
- Enable zkSync Era payouts, fix wallet description
- Fix deploy flow: build full spec from YAML, resolve ${VAR} in volumes
- Remove manual Docker deployment sections from guides
- Add dashboard table sorting, update service guides and configs
- Clean up guides and README: remove auto-generation, streamline docs
- Stop auto-generating README tables, keep README manually maintained
- Rewrite README for UI+Worker architecture, add guide links to tables
- Service audit: update statuses, fix Anyone Protocol, add graveyard
- Clarify README: CashPilot tracks both Docker and non-Docker services
- Add dashboard screenshot, bind MystNodes UI to all interfaces
- Update platform support for all 22 services
- Green border on deployed services, remove earnings badge, add Docker platform
- External services: show -- for health, add disconnected label
- Update ProxyBase/EarnApp info, make dashboard rows clickable
- Fix Bytelixir collector to handle URL-encoded session cookies
- Clean up AGENTS.md: remove deployment examples and private topology
- Update AGENTS.md: service statuses, new referral codes, URnetwork API, setup guides
- Add URnetwork referral code, mark Peer2Profit and PacketShare as dead
- Add 12 new services, update statuses and referral links
- Update bcrypt requirement from <4.1,>=4.0 to >=4.0,<5.1 (#3)
- Bump python from 3.12-alpine to 3.14-alpine (#2)
- Remove bonus referral fields from all services, update statuses and links
- Show all services, fix platforms, verify URLs
- Add constants.py to worker Dockerfile
- Skip catalog services without Docker image instead of loading them
- Fix worker reporting duplicate containers when m4b uses same images
- Enable grouped security updates
- Fix topbar earnings on all pages and theme label duplication
- Navbar Option C: avatar dropdown, move GitHub/sponsor to sidebar
- Fix fleet page: remove local instance card, clean container badges
- Redesign navbar: cleaner layout, currency selector, mobile responsive
- Reduce dashboard auto-refresh to once per hour
- Fix expanded service rows collapsing on auto-refresh
- Fix CI: release workflow calls build directly via workflow_call
- Move container label constants to shared constants module
- Split UI from Docker: UI never touches Docker, all ops via workers
- Implement CASHPILOT_MODE=ui for Docker-free UI container
- Auto-release patch versions on push to main
- Bump python from 3.12-alpine to 3.14-alpine (#1)
- Add multi-currency system with exchange rate conversion
- Add collector alert notifications in navbar
- Add Grass and Bytelixir earnings collectors
- Add Ebesucher referral link
- Add Bytelixir referral link
- Show manual-only services with platform notice in setup wizard
- Show spinner instead of error when loading services
- Add SECURITY.md, sponsor button, fix cold-start dashboard timeout
- Add 400-day data retention and update deployment docs
- Add federation architecture spec and update collector status in AGENTS.md
- Add CI check to agent checklist in AGENTS.md
- Add privileged mode, command template substitution to orchestrator
- Add per-service earnings breakdown and manual claim flow
- Add collector credential forms to Settings page
- Add Storj storagenode earnings collector
- Add cashout button to deployed service cards
- Add IPRoyal Pawns earnings collector
- Add cashout section to schema and all 39 service YAMLs
- Add earnings dashboard API endpoints and fix route mismatches
- Add earnings collectors for EarnApp, MystNodes, and Traffmonetizer
- Add 12 new service YAMLs from competitor analysis
- Add mobile phone earning to roadmap, remove completed theme item
- Add dark/light theme toggle and GitHub link to navbar
- Add multi-node federation docs and fleet env vars to README
- Add CashPilot app icon (synthwave sun from banner)
- Add security FAQ: Docker isolation, hardening, and honest risk assessment
- Add FUNDING.yml
- Add one-click cashout button to roadmap
- Add federated multi-node fleet management (v1.2)
- Add CI/CD: linting, CodeQL, releases, dependabot, ruff formatting
- Add 10 starfield banner iterations, remove shooting stars
- Add 10 synthwave banner iterations for selection
- Add 8 banner candidates and federated master/child architecture
- Add container discovery labels and fallback lookup
- Add dual operating mode, compose export, and slim Dockerfile
- Add autopilot compass logo, ROADMAP, remove earnings estimates, update competitors
- Add authentication system with user roles and onboarding
- Add workflow_dispatch trigger to CI
- Add project banner SVG and replace README header
- Add referral codes for 13 services and update Repocket
- Fix ruff formatting in main.py
- Fix action buttons: visible, consistent size, instance badge in status
- Fix Grass collector: use /retrieveUser endpoint for totalPoints
- Fix Grass token hint: accessToken in localStorage, not console
- Fix Bytelixir collector: use session cookie (hCaptcha blocks login)
- Update Grass URLs from getgrass.io to grass.io
- Fix Bytelixir and Grass platform info from research
- Fix ruff formatting in orchestrator.py
- Remove dead services, fix platforms, detect external containers
- Remove redundant url_template and code fields from referral config
- Remove how_to_get_code from service definitions
- Fix setup wizard: filter non-deployable services, improve selection UX
- Fix category cards not responding to clicks in setup wizard
- Fix inconsistent cashout button width between enabled/disabled states
- Fix action button tooltips and consistent cashout button width
- Remove private server details from AGENTS.md
- Fix ruff formatting
- Fix duplicate earnings and lint error
- Fix ProxyRack collector: add required headers for API call
- Fix collector config: optional args, correct Supabase key, JWT token support
- Fix and add earnings collectors for all 10 services
- Fix Mysterium collector: add auth support, use correct API endpoint
- Fix host network mode incompatibility with port bindings
- Update roadmap: mark breakdown, claim, and health scoring as done
- Update roadmap: mark dashboard API and cashout YAMLs as done
- Update roadmap: mark EarnApp, MystNodes, Traffmonetizer collectors as done
- Fix Docker socket permissions and apply banner color palette
- Update roadmap: mark implemented federation features, fix service count
- Clean up README: remove referral config section, add legal disclaimer, add Type column
- Remove dead services, fix referral info
- Fix registration 500: pin bcrypt<4.1 for passlib compat
- Fix Alpine Docker build: GID 999 already in use
- Update fleet management spec with WebSocket agent architecture
- Fix license to GPL-3.0, fix Starlette 1.0 TemplateResponse API, add competitors
- Fix Gradient referral URL param and mark SpeedShare as broken
- Expandable instance rows, per-node earnings, notification bell always visible
- Copy status cache before appending worker containers (was mutating shared cache, growing instance count on every API call)
- Rename Total Earnings to Total Balance, fix first-day delta
- Always show instance count badge (1x, 2x, etc) for Docker services
- Aggregate services by slug, show instance count and external services
- Mark PacketShare and WizardGain as broken, remove from README
- Auto-refresh dashboard 10s after first load for fresh stats
- Cache container stats for instant dashboard loading
- Replace WebSocket federation with UI + Worker architecture
- Revamp README tables: richer columns, referral links in service names
- Redesign dashboard: unified services table with referral links
- Redesign onboarding UX: setup mode selection, preferences persistence
- Synthwave UI overhaul: navy-purple palette, rose/cyan accents, frosted glass
- Replace compass icon with synthwave sun across web UI
- Center banner vertically, embed referrals in service links
- Overhaul README service table with device limits and IP compatibility
- Finalize synthwave starfield banner, remove all candidates
- Optimize Docker image: Alpine base, drop tini, venv pattern
- Rewrite AGENTS.md with comprehensive service status and agent guide
- Initial release: CashPilot passive income platform
- Initial commit