Changelog

Design surface, and the App Store

Jul 7, 2026·37 min read

One of the biggest weeks yet. Contrast gained a real Design surface: lay out every screen of your app on one canvas and restyle it live. The mobile app was rebuilt around a swipeable pager that sits chat and previews side by side, and you can now ship an app all the way to TestFlight and the App Store from a single guided flow. Underneath all of it, sync moved onto dedicated Rust hosts, SootSim now paints and animates on its own frame clock, and a July 8 production incident led us to rebuild the safeguards that protect your data from the ground up.

Platform

A design surface for your whole app

The Design view is no longer a hidden experiment. It’s now a permanent destination you can open in any project, with its own tab on mobile and a full-screen home on the web, and its open state rides along in the link, so a reload or a shared URL lands you right back in it. Open it and Contrast walks your app through its routes, laying every screen onto a canvas as an artboard, complete with paired light and dark variants and the deeper flows it reaches by following seeded navigation branches through real navigation. Panning and zooming feel right, transparent screens sit against a checker background, and fit-to-view and actual-size are each a keystroke away.

None of it is a static picture. Hover a node and it names the component, with a quiet readout of its route, owner, and source; select it and you get navigable Tree, Layout box-model, and Styles views. And you can go further: edit your app’s design tokens, its colors, spacing, and type, and every captured screen re-renders live against a single source of truth.

open the Design tabyour screens laid out aslight and dark artboardshover a node to see thecomponent, route, andsourceedit a color, spacing, or typetokenevery captured screenupdates live

The mobile app, rebuilt around a Develop pager and floating previews

Chat and preview now live together in one swipeable Develop pager on the mobile project screen, so you stop bouncing between separate destinations. The swipe feels connected too: a drag streams the preview continuously into view and tracks your finger instead of snapping partway there, and switching projects resets the pager cleanly rather than replaying the motion. Live web and iOS previews open fullscreen and tuck away into a single shared floating picture-in-picture stack instead of scattering through the chat; expand one in place and you get focused web controls, including a way to open it in the system browser without leaking your login. And when an agent says “show me” a screen, that request reliably reaches your phone and opens its own view with the exact screen it meant, even when no matching desktop pane exists.

A broad refinement pass rode along with it. Sheets and floating buttons now share one frosted-glass look, and the native glass material was fixed so it actually renders and stays visible when a sheet is reopened. From a chat card you can open the real product spec in a standard document picture-in-picture; the login screen uses the real Contrast logo; the header blur fades over a longer themed gradient; and the mobile editor picked up jump-to-source.

Mobile chat you can trust, with a live view of the crew

Send a message from your phone and it saves, then the assistant’s reply comes back, every time; a send used to be able to vanish with no response at all. When you send, the chat jumps to the newest message, stale thinking spinners now clear themselves, and reopening a project that’s been sitting idle shows a calm reconnecting state rather than an alarming error. The activity card has turned into a live roster of the agents building your app, one line each with a status dot, a name, and the latest meaningful thing that agent did, ordered by when they joined and kept on screen through idle and done, with duplicate rows filtered out. Sending surfaces send progress and live factory state right away instead of after a round-trip, and opening a project quietly warms its cloud build in the background so the assistant is ready sooner. The composer gained voice dictation as well, powered by Apple Speech, with a stop control and a live indicator, plus a compact attachment rail and model-selection actions.

Watch and run deploys from your phone

There’s a real Production tab in the mobile app now. From it you can tell whether your app is live, watch a deploy move through the queue, open any deploy to read its logs as they stream in, check custom-domain status, jump straight to the live web or iOS app, and kick off a deploy without leaving your phone. The latest deploy is pinned above the recent ones, each tapped deploy carries its build logs on its own screen so back navigation works, and one header Deploy button opens a bottom sheet with matching Web and iOS choices that gray out while a deploy is in flight. Empty projects greet you with a centered mascot, and harmless build lines like “0 checks failed” no longer show up colored as errors.

Ship to TestFlight and the App Store from one guided flow

Publishing an iOS app used to be a chain of manual buttons; now it’s one guided flow that spans internal and external TestFlight testers and full App Store submission. Approve it once and the release drives itself: it pins the exact build to the exact store version, pushes the listing, screenshots, and review info, waits for your approval, submits, tracks the review, and releases. Along the way you can hand it reviewer demo-login credentials, which fail loudly rather than send stale secrets if they’ve drifted, cancel a review in flight, and get an email at each stage. Only one deploy drives at a time, cancelling truly aborts the run instead of leaving it half-finished, and production monitoring flags any release stuck needing manual action for more than a day. All of it was specified, adversarially reviewed by a second agent, and corrected across several rounds before it landed.

Live, multiplayer project rooms

Projects are live and multiplayer now. Open the same project as a teammate and you’ll each appear with a name and a personal color, while the project chat shows who is present and what they are saying. Only real members of a project can join its room.

Invite teammates with per-repo access

Invite teammates into an org and you control what each of them sees. Choose which repos a person gets and whether their access is full or limited; even limited members can open live screenshot capture on private builds. Anyone who joins through your GitHub org membership gets org-wide full access automatically.

Buy hosting and a custom domain right in the product

Hosting and a custom domain are now add-ons you buy right inside Contrast, through clear purchase and removal dialogs, and production web deploys draw on what you have paid for, free allowance included. Hosting management survives a reload, and a run of edge cases got closed along the way: an unlinked hosted repo returns a plain payment-required message, a reserved hosting slot is freed if its first deploy dies, duplicate-purchase and orphan-charge races are handled, and a false seat cap is gone, since teams have no seat limit.

One Pro subscription across Contrast and SootSim

Plans now come in a clear Free, Pro, and Enterprise lineup shared across both products. Pro is a single subscription covering Contrast and SootSim with transparent usage-based pricing, and a free trial can run one cloud factory. The pricing page was rebuilt to match, with responsive cards, stronger typography, and clearer copy about what each plan gives you.

A cohesive editor and workspace refresh

The editor got a cohesive visual pass. Panels sit on a softer, borderless surface with consistent rounding and depth in place of ad-hoc borders, selection states read the same everywhere, and the settings dialogs (billing and pricing, project access, GitHub, secrets, the onboarding scan) were rebuilt on one shared layout, with the custom-domain, Apple-connection, and deploy dialogs recast as clear icon-led, step-by-step flows. The workspace overview shifted character too. Staged app panes are live, usable surfaces right where they sit, the tap-to-lightbox layer gave way to a maximize button, non-phone panes reflow to split whatever width the phone leaves, and the dock auto-hides down to its section labels, sliding up over the stage on hover instead of stealing height.

Generated apps start with real demo data

Generate an app from a template and it opens with real demo data instead of a blank screen: a starter todo list, a demo leaderboard for games, budgets for the finance example, trips for travel. Apps built around shared data seed shared entries, apps built around per-user data seed per user, and either way the very first run already looks like a working app.

Apps display text in nearly every language, in the real iOS typeface

Apps built in Contrast now render text in almost every language iOS supports, in the authentic system typeface, rather than falling back to a blank or mismatched font. It started with Vietnamese and other extended-Latin characters, then grew into a loader that pulls a given script only when an app actually shows characters outside the basic set, and it now reaches 35 language subsets spanning Arabic, Hebrew, Thai, Devanagari, Chinese, Japanese, Korean, Armenian, Georgian, Tamil, Telugu, Bengali, Khmer, Lao, Myanmar, Sinhala, and more. A caching fix means a font that arrives after the first frame no longer leaves the text blank.

Tech

After a runaway write burn, a shutdown that can no longer destroy data

Last week’s cost tripwires caught a slow burn. On July 8 a much faster one, roughly a million rows a minute, tripped the external 200-dollar-a-day auto-shutdown, and that shutdown force-deleted the data-demo worker. Deleting a Cloudflare worker deletes its Durable Objects along with it, so all of production data went too and had to be restored from the 07:13Z R2 backup. So the whole safeguard chain was reworked until a runaway can no longer cost data. Data workers now sit in a never-kill set, which leaves the auto-shutdown able to delete only disposable workers, and for a data worker the cost monitor now trips a circuit breaker rather than deleting anything. That breaker is admin-gated and stops writes with no redeploy and no deletion; it trips at 200k rows a minute soft and a million a minute hard, catching a real runaway in a minute or two, and the July 8 burn ran at about a million a minute, half the old soft default. Rounding it out, a one-command full-fleet R2 restore was added, empty exports can no longer overwrite the latest-backup pointer, the singleton keeps 30 dumps, and the app-worker crons collapsed into a single test-enforced registry.

runaway writes, about 1Mrows per minutebefore: daily-cost tripforce-deletes the workerdeleting the worker deletesits Durable Objectsall prod data lost, restoredfrom the 07:13Z R2 backupafter: data workers sit in anever-kill setadmin circuit breaker stopswrites, no delete and noredeployauto-shutdown can nowdelete only disposableworkers, never data

SootSim renders on its own frame clock

The CanvasKit painting of a running app used to happen inside the shell worker, the one that owns iOS chrome and native UI. It has been split out into its own compositor worker with an independent frame clock, so a busy host thread can no longer freeze rendering. The split started gated behind a flag with the default engine untouched, then over the week became the default, owning the primary app surface end to end. The hard part was carrying everything the shell did locally across the new boundary. Scroll, pinch, and zoom physics are still computed shell-side, then forwarded over a bidirectional tree port and re-applied to the compositor’s own mirror by wire-id before its next paint, and color scheme is synced so glass and blur chrome match the app. Every ~400ms the compositor throttles a downscaled bitmap of its canvas back to the shell, which keeps the app-switcher card and the keyboard and alert blur backdrops from ever going blank. Motion made the move as well: native-stack transitions, fling and momentum scrolling over shared physics math, and reanimated layout animations now step on the compositor clock rather than on React, home-surface painting came across too, and every surface is tied to the app generation that owns it, so a rebound surface can never drive a stale animation. Memory got attention as well: per-surface GPU cache counters purge idle caches, and a seed-300 run held the GPU flat while total memory grew 44 to 60MB, well under the 150 to 300MB a texture duplication would have cost.

Frame delivery while the host thread is peggedHost thread rAF (before)491msCompositor rAF (after)~8msthe compositor worker's own frame clock keeps painting through repeated main-thread freezes

Reanimated and Animated, aligned with real React Native

A large correctness sweep brought SootSim’s animation runtime into line with real React Native. Animated value and interpolation semantics were realigned, default timing was matched to RN, and reset-listener semantics were fixed. Worklets, meaning frame callbacks, keyboard progress, sensors, and shared-value animations, now run at the shell event source with a proper lifecycle: registries release on unmount, runtimes get disposed, peers stay isolated across tenant replacements, and detached or stale native targets are rejected. Native animation ownership is qualified across surface generations and worker boundaries, and gesture composition is arbitrated in the shell runtime instead of a much larger gesture-handler stub, all of it closed against an animation-runtime parity matrix.

Production sync moved to dedicated Rust hosts

The sync layer’s move to Rust went from scaffolding to a real production cutover this week. It opened with a preparation harness that proved offline pull-equivalence: an on-zero adapter, a schema, dev and production auth variants, a Cloudflare worker, cutover and rollback scripts, and executable suites showing the Rust path returns byte-identical results to the current transport before any flip. From there, production clients moved onto dedicated per-deployment Rust sync hosts, each with real query transforms, its own auth path, deployment-target routing, and staging-data rotation. Cutover writes were metered so legitimate project creation stays under the Durable Object write-budget breaker, and legacy namespaces are hydrated before Rust takes a snapshot. The flip itself was cut, reverted once when it caused trouble, then re-cut and completed, with production evidence recorded and the write budget raised so the breaker stops tripping on normal traffic.

Local dev runs on a native Rust host over one SQLite file

Local development dropped the embedded-Postgres-plus-zero-cache topology for a single native Rust binary backed by one SQLite file in WAL mode, shared between the app worker and the sync host. The sync host speaks Zero v51 pull and push; mutations flow through the app worker’s API and land in SQLite via drizzle, and change-capture triggers record those writes into a change log so Zero clients pick them up on the next pull. Bridging the two worlds is a Postgres-to-SQLite compatibility pool that converts parameters, rewrites now(), ILIKE, and casts, maps date columns to epoch millis, no-ops advisory locks and transaction markers, and translates the json_agg and jsonb_agg aggregates SQLite lacks (a rewrite that has since moved into pg-to-sqlite itself), which is what stops local project provisioning from returning 500s. Schema convergence runs at backend boot, at pool init, and at a per-namespace runtime barrier, config and DDL are generated for all 38 tables, and the setup seeds an anon user, a personal account, and a default project alongside a local S3 server, with Zero mutations executing inside project-native SQLite transactions that match production semantics. Postgres in CI and production is unchanged.

before: embedded Postgresplus zero-cache plusseparate processesafter: one native Rustbinary plus one SQLiteWAL fileshared by the app workerand the sync host,converged to the Zeroschema

Project sync became a stateless HTTP pull

Per-project sync went from a stateful connection to a stateless HTTP pull-and-push transport. On Cloudflare it serves cursor-based diffs, on Node it serves scoped snapshots, and the client uses the Postgres write-ahead-log position as its pull cursor for complete change detection. It enforces per-request transfer caps and cookie ordering for correct visibility, and it was audited for primary-key immutability and no derived writes. The change rode an opt-in flag that came out once HTTP pull was the only project transport, settling on a 15-second poll. Routing shed its hand-rolled projectId-from-pathname regex too, and now leans on Orez’s generic sync-server mount with a per-project DB adapter, verified byte-identical across the id charset, boundaries, verb handling, and malformed paths.

Custom-mutator pushes route through the data worker

On the split control plane, a Zero custom-mutator push would re-enter the app worker the moment it opened its transaction, trip Cloudflare’s subrequest-depth limit, and drop the write, most visibly the mobile chat messages that never landed. Pushes now route through the dedicated data worker with no re-entry at all. Getting there meant splitting a batch of agent and identity modules into client-safe domain files, stubbing server-only code in the Durable Object worker bundle so the push handler could initialize, aliasing drizzle-pg, and installing the SQL DO registry on the push path, with a new graph check guarding the boundary. A direct chat endpoint added as a transient stopgap was deleted once pushes routed correctly, so there is a single write path again, while reads stay on the unchanged sync path.

before: mutator push hitsthe app workeropening its transactionre-enters the app workerCloudflaresubrequest-depth limit,write lostafter: push routes to thededicated data workerwrites to the sql DurableObject, no re-entry

Untrusted packages build inside a locked-down container

To score coverage, the compat pipeline builds arbitrary third-party React Native packages, and building them means running untrusted install scripts. That work now happens inside a two-phase ephemeral Docker box: it installs on an internal network whose only exit is an allowlist proxy for the npm registry and github, then metro-bundles with the network fully off. The container runs non-root and capped on memory, cpu, and pid, with no host filesystem mounted beyond a single output directory, which closes the host-pivot hole the old VM approach left open by mounting host home and allowing open egress. An adversarial test proves five containment properties, and the box was proven end to end on zulip-mobile with a 7.7MB offline bundle, with stream-chat, metamask, and gutenberg recipes added afterward.

untrusted packagephase 1: install, egress onlythrough an allowlist proxy toregistry and githubphase 2: metro bundle withthe network fully offwrites only to an outdirectory, non-root andresource-capped

Private user data split from the synced public profile

Auth was restructured so private user data lives physically apart from a synced public-profile table. Public-profile reads and writes moved into their own query and mutation modules, and the sync layer only ever carries the public projection, which keeps private fields from ever leaving the server through the sync path. It shipped with a schema migration.

The hosted PR-preview recorder, unwedged

The hosted GPU recorder that turns a PR into a preview walkthrough had gone silently dead, in three separate ways. First, Durable Object SQLite reports a row count of zero for every write, so the job-claim’s null-check fired even right after it had flipped a row from queued to running; every claim came back null, the recorder re-polled, and rows rotted as phantom running jobs no recorder ever ran. The claim now reads the row up front and returns it via RETURNING, which also closes a read-after-write gap. Second, the pod bootstrap never installed node and npm, which the run script needs to install sootsim and playwright, so a claimed job just stalled; the bootstrap now installs them. Third, the pod had no gh CLI and no business pulling a private-repo diff with the customer’s token, so the diff came back empty and every walkthrough skipped with no changes to preview; the PR diff is now carried through the job queue and handed to the run script directly.

Abuse and cost hardening

After the write burn, the paid agent’s web-search and web-fetch tools picked up per-account rate limiting so an agent cannot hammer outbound requests. Admin-only and dev-only routes now enforce their guards through a shared deny-in-prod helper, backed by a new CI check that fails validation on any unguarded admin or dev route. The Zero mutation surface got the same treatment: unused auto-generated CRUD slots were removed, the deployment update slot was constrained to cancel-only writes, the remaining raw slots got constrained validators, and a standalone guard enforces that every mutation has a coverage slot while rejecting two-argument mutations. The sync layer no longer exposes the generic write access clients could have exploited, and all of it is now machine-checked.

The Cloudflare deploy path, hardened end to end

A production login outage traced back to a worker that could not boot because libpg-query’s WebAssembly was not precompiled for Cloudflare. The fix ships it as a precompiled attachment and keeps the local-only SQL compiler out of the Cloudflare app bundle entirely; once Orez 0.5.7 made that precompile native, the redundant workaround came out. Worker secrets now upload atomically with the deploy version, so a deploy cannot half-apply, and a missing telemetry environment variable can no longer block a production deploy. The path that boots each app’s data backend was made resumable: pending and in-progress boots are persisted and resumed via alarms so they survive worker restarts, warm-up probes stop hammering a backend once it hits a terminal failure, terminal failures surface a real reason instead of a generic timeout, and native replica warm-up is bounded to a fifteen-minute ceiling so large snapshots can finish before a deploy is declared failed. A related fix stopped an out-of-memory loop during embed boot by shedding incoming sync while it is still booting, recording a persisted boot-failure backoff, and gating the schema-metadata write so it runs only outside the reconnect path.

SootSim

  • SootSim device frames now carry Apple’s Simulator geometry across all 13 modern iPhones, after pixel-measuring seven booted Simulator windows; a recent refresh had switched them to thicker physical-phone bezels and seated the side buttons 22 to 50pt too low.
  • Screen corner radii are now circle-fit from each device’s own framebuffer mask, and the status-bar clock and icons center on the dynamic island like real iOS.
  • expo-video is a real native seam now: the host decodes the video and streams frames into the compositor, so apps using it paint their first frame and play.
  • Bluesky’s composer loads again after a paste-input compatibility stub that exported the wrong element was fixed, and a requestIdleCallback polyfill in the tenant bundle stops Bluesky’s lightbox crashing in worker scopes.
  • react-native-pager-view sizes its pages correctly and streams drag progress continuously, so a swipe follows your finger and the landed page is decided only once release velocity settles.
  • Continuous-corner squircle shapes now honor the four individual corner radii Tamagui and flattened StyleSheet produce, instead of painting as plain squares.
  • Reanimated scroll worklets run on the shell worker fed by real scroll input, fixing animations tied to scroll position (validated against Uniswap), which now boots after two compatibility surfaces were made to mirror the real packages.
  • Real spinning iOS date, time, and option-picker wheels now render where a dead placeholder used to sit, including the community date-time picker and the React Native picker.
  • Launching an app directly or from the dock no longer hangs on “Painting home”, pushed native-stack cards start offscreen so they always slide in cleanly, and pan gestures survive re-renders and strict-mode double effects.
  • Native tab bars stay in sync with the app’s router in preview.
  • Visual polish on the SootSim home and device frames (sharper transformed glass, a centered de-tinted dock, smooth continuous corners), plus new designer background palettes and live Apple-Air switching in the 3D device showcase.
  • Setting up SootSim now uses a plain, readable install script instead of an opaque one-liner, with the docs linking to its source.
  • A new film command records a flow at full speed, then replays it on a 3D phone stage under a camera script and captures the WebGL stage to an mp4, shipping reusable Bluesky and Uniswap demo flows.
  • The test runner keeps its progress display current, hides waiting steps, and replays a plan after the simulator rotates; Playwright sims now connect through a drifted WebSocket bridge port instead of connect-timing-out.
  • A react-native-quick-crypto native seam unblocks the Joplin demo, tap verbs refuse to dispatch on an offscreen center and fail fast with a scroll-first hint, and text taps now match accessibility labels so icon-only controls are reachable.
  • Engine-internal correctness: raster caching now engages on 3x-density devices by gating on points area instead of raw pixels (text draw calls down 25x on a Bluesky scroll), app surfaces paint under WebKit and Safari from an export-free entry, and native-seam fidelity fixes landed for OneSignal, device-attest, and Reanimated shadow-node tags.

Mobile app

  • A four-page swipeable intro shows the kinds of apps Contrast builds before you sign in with GitHub, appears once, and remembers you have seen it.
  • Native Sign in with Apple on the login screen, with the Apple identity verified on the server.
  • Long-press a project to rename or delete it, with a redesigned plan board that feels like a native list and a task detail split into its own view.
  • Report an assistant response or other content through a dialog.
  • When an update is downloaded you can tap Restart now to apply it immediately, with the control reachable by screen readers.
  • Material polish across the app (cleaner composer placeholder, removed stray borders, consistent rounded corners on projects, dialogs, and login) plus a redesign of the project header, projects tab, and template-picker cards with better dark-mode contrast.
  • Build and live deploy logs open as two separate real screens so back navigation works, and the project header backdrop fades as you scroll.
  • Steadier preview and new-project handling: renaming updates the header instantly, a rejected preview session shows an error instead of spinning forever, the latest deploy stays pinned to a usable live target, and freshly created projects wait until they are ready before running.
  • Tapping a text field no longer dismisses the keyboard, after a Tamagui 2.4.5 upgrade restored a theme registry entry that strict-mode was wrongly deleting.
  • Mobile auth switched to static Expo and aligned Better-Auth imports so the Hermes build resolves them, unblocking the TestFlight build path.

Examples and templates

  • The Sprout pet example got a personality pass, with idle tells, touch reactions, and little care choreographies in warm themed chrome, building on last week’s creature species and leaderboard.
  • The example todo app no longer ships a leftover instructional welcome row, so a fresh list starts clean.
  • Horizontal card rails in the flights example now keep page gutters on the web instead of bleeding to the edge, and the lists-and-feeds guidance the factory follows was updated to match.
  • Sign-in and other auth buttons in the finance, travel, pet, and rpg starters now stay above the on-screen keyboard.
  • After a main production deploy, CI rebuilds and re-publishes only the community example apps whose source changed, so the live examples do not drift behind the code.

Website and design

  • The landing page’s large above-the-fold backgrounds were re-encoded much smaller (the aurora from about 513KB to 146KB) for a quicker first paint.
  • The home page now reveals each section as you scroll with directional staggered animations, and animates in as a timed, top-to-bottom sequence of header, headline, prompt, subtext, showcase, then mascot.
  • Site typography moved to a single variable font carrying seven width families in one download, so headings render true intermediate weights, and the mobile onboarding hero shows the real typeface.
  • The SootSim explainer page was rewritten to lead with what SootSim is and why it beats a webview, then walk the current compositor-worker architecture and conformance, and the SootSim site now leads with building before testing.
  • The how-it-works engine pages were rewritten shorter and plainer, marketing headers and the SootSim pages got polish, the pricing page dropped an unsupported preview-history claim, and invite success screens gained a see-what’s-new link to the right changelog.

Editor and preview

  • Settings, integrations, production, and the factory selector share one card style, and cards no longer collapse and overlap at narrow widths.
  • Tool-call and action cards in chat transcripts are simpler with less chrome, and an inspected element handed to the assistant shows up as a tidy context card instead of a raw dump.
  • The command menu can jump between your workspaces and the overview panes by keyboard.
  • The element inspector now targets the actual components rendered in your live preview on both web and native.
  • The web preview honors real device safe areas, and now fails loudly on missing framework assets instead of reporting a false mount success.
  • The native preview simulator menu was pared to an appearance toggle plus the device and debug menus, and the deploy view moved its build log into a focused dialog with a dedicated custom-domain flow next to Deploy.
  • The screenshot strip generator lets you swap in your own replacement screenshots while keeping the full device frame, captures now include the header and tab-bar chrome painted separately, and shared preview trace-map artboards paint on production.
  • PR preview comments now include an auto-generated Maestro test flow a reviewer can run against the preview, and native previews under WebKit isolate their worker module graphs so tenant bundles cannot cross-contaminate.

Deploy, sync, and infrastructure

  • Deleting a project is now reversible: it is marked for removal and cleared by a scheduled background sweep, so an accidental delete has a recovery window.
  • Creating or forking a project waits for the server commit before navigating into the new namespace, so a freshly created project reliably loads its own data, and first writes plus branch and task routes commit the access record before any permission-dependent work.
  • Shareable hosted-simulator preview links resolve immutable pointers so a shared URL never silently jumps to a newer deployment, and a local deploy is advertised as an mDNS record so the iOS simulator and other devices on the network can reach it.
  • Cloudflare deploys register schema tables when they take Durable Object snapshots, generated data-tier transaction batches serialize across worker modes, and production deploys ship every schema-coupled plane together while rejecting dirty sources by name (Orez 0.5.0).
  • Two regressions that blocked every dev IDE from booting were fixed (SQLite-shaped SQL sent to Postgres, and an emptied auth secret), and raw-SQL bare-alias 500s were fixed on five production paths.
  • Comped teams can build again after their subscriptions were resolving as free once the free grant ran out, and preview uploads plus durable builds for the same commit stopped billing twice.
  • Operators now get alerted once when a PostHog exception signature spikes, an independent reaper kills orphaned RunPod pods even when no dispatcher is alive, and a rate-capped production demo login lets Apple’s reviewers exercise the app without real credentials.
  • Preview-worker cookies are now host-only and cloud preview sessions stay pinned to their own origin, and a team auto-join’s membership reads now run inside the join transaction.

AI and the factory

  • Grok-4.5 is selectable as an agent model through OpenRouter, with agent creation now stripping invisible characters and validating against the model registry so a hallucinated model id can no longer crash-loop a runner.
  • Two recurring quality gaps in agent-built apps were closed: the acceptance agents follow now requires every named screen to be distinct and complete, and requires floating controls to reserve space and prove each tab is individually tappable.
  • The factory now describes what a captured screen actually shows in plain terms rather than internal jargon, and the building agent gained a tool that lists available registry templates so it picks a starting point instead of guessing.
  • Spend decisions and user-input escalation for the paid image and asset tools route through the main agent’s decision flow, and hosted factory runtime requests are bounded with enforced timeouts.
  • The cloud factory enforces per-member leases on browser and cloud execution so one member’s headless runs cannot collide, and the contrast dev CLI dropped brittle port-regex detection for a typed runtime descriptor that drives both local dev and the factory.
  • The “what the agent is doing right now” speech feed is now published as durable sync events, so desktop and mobile project the same live work snippets instead of only the desktop that produced them.

Fixes & polish

Beyond the headline work, 477 fixes and 8 performance improvements landed this week. A few worth calling out: sending a message from the mobile app now reliably saves and returns the assistant’s reply, where a send used to be able to vanish with no response at all; tapping a text field on mobile no longer dismisses the keyboard on the first touch; and the SootSim desktop app now starts for a user without admin rights, where a first-run install into a system-wide location used to stop its background service from starting.

Ready?

Create a web, iOS, and Android app in minutes with agents working alongside you.