Prompt Changelog
Each report published here is stamped with the version of the analysis
prompt that produced it — visible as a small v1.x.y chip on the
report card and in the report footer. This page summarizes the
prompt-level changes that shaped each version's writing.
Version scheme:
- MAJOR (
x.0.0) — structural changes to how a report is laid out. - MINOR (
0.x.0) — meaningful improvements in analysis quality. - PATCH (
0.0.x) — small refinements and copy adjustments.
Older reports keep their original stamp; new versions apply only to reports generated after the release date.
v1.9.0 — 2026-08-27
- Each security-fix commit now carries a process-boundary flag alongside the existing bug type. The flag is true when the bug lives in a WebKit process other than WebContent (UIProcess, GPUProcess, NetworkProcess, adjacent codec / ANGLE / display-list paths) and is reachable from WebContent. It captures the exploit-developer distinction that the mechanism-only labels lose — a use-after-free in a graphics-process display-list decoder differs meaningfully from the same bug in WebContent's DOM, because any successful exploit would land across the sandbox boundary. The flag tracks location + reachability, not exploitability itself; whether a given bug is actually reachable end-to-end is a separate analysis question. The flag is orthogonal to the bug type: a commit can carry both. Reports and cross-week listings surface it as an additional signal without narrowing what the bug type itself means.
v1.8.0 — 2026-08-26
- Pipeline model upgrade. Every LLM stage is now running on the latest generation — Sonnet 5 for classifier / dev digest, Opus 4.8 for security analyst / fact checker / writer / curator. The translator specifically moves up a tier (Sonnet → Opus 4.8) so Korean output gets the same care as the English composition, particularly for technical-term context judgment. Reports generated after this stamp should read as slightly sharper root-cause writing and more natural Korean prose without any structural change.
v1.7.0 — 2026-08-20
- CVE-analysis pages now include an Insight section between Analysis and Audit directions, matching the shape weekly per-commit pages already used. The section is optional — skipped when the bug is a plain missing check with no reusable lesson beyond the root- cause label — but its presence lets the reader walk away with a takeaway rule of thumb or a broader-context observation the CVE library previously compressed into one line.
v1.6.0 — 2026-08-19
- Security-fix commits now carry an explicit bug-type label from a fixed taxonomy: UAF, OOB, TypeConfusion, IntegerOverflow, Race, UninitializedMemory, MemoryCorruption, SandboxEscape, CrossOrigin, AuthBypass, InfoDisclosure, LogicError, Other. The label appears as a chip on each report row and drives the dashboard view of what kinds of security bugs WebKit is shipping over the recent window.
v1.5.0 — 2026-08-17
- The pipeline now distinguishes preventive hardening (added guards, mitigation adoption like MTE/PAC/CFI/gigacage, sandbox tightening, capability reductions) from vulnerability fixes as a separate signal. Direction-aware: commits that remove checks, disable mitigations, or loosen policy stay outside the hardening bucket. A single commit that both fixes a bug and adds surrounding guards can carry both.
v1.4.0 — 2026-08-17
- Development-track picks broadened. Real "development highlights" (new Web API landings, major architectural shifts, JIT/GC landmarks, spec milestones) were previously excluded from the weekly report because the ranking assumed a single exploit-relevance scale. Add a scoring path that lets these commits qualify without any exploit primitive, so they surface in the Notable Development section. Security-fix ranking and threshold unchanged.
v1.3.3 — 2026-08-13
- Per-commit page URLs are now derived from the same fixed-length commit-hash prefix on every report. The writer is required to emit the full commit hash so URLs never differ between runs for the same commit.
v1.3.2 — 2026-08-11
- Contributor profile summaries no longer cite specific commit counts in prose. Those numbers already appear as live badges and a component bar on the same page — keeping them out of the narrative means the summary stays accurate as new commits land, instead of drifting behind the badges over time.
- Summaries also refresh automatically now for contributors who stay active — either every four weeks or after ten new commits land, whichever comes first. Previously each summary was written once at the contributor's first appearance and never updated.
v1.3.1 — 2026-08-11
- Reports now clearly distinguish "browser chrome" (the UI framing — toolbar, tabs, URL bar) from the Chrome browser, avoiding a term collision that read as the Chrome browser in earlier reports — especially in Korean translation, where the English word "chrome" is naturally parsed as the brand.
v1.3.0 — 2026-08-02
- Dev-commit entries in the Notable Development section now show the affected component and a direct link to the commit on GitHub, matching what security fixes already carry. Earlier reports could ship dev commits with neither, leaving the reader without either the "where" or the jump-off to the diff.
v1.2.0 — 2026-07-27
- Reports now warm the reader up on general concepts before diving into WebKit-specific type names. The first sentence of each security-fix write-up frames the kind of bug and kind of subsystem, rather than opening with unfamiliar class names the reader hasn't seen defined yet.
- The one-line "angle" that names what an attacker gains is now written in plain terms — canvas rendering, IPC, thread races — instead of five internal type names strung together.
- For broad changes that touch many files, the technical patch section now opens with a one-sentence outline of what the change is doing in 2-3 pieces, so the flood of function and class names that follows has a small map to sit against.
v1.1.0 — 2026-07-26
- Audit suggestions now honestly acknowledge when a bug's underlying pattern is tied to WebKit-specific machinery — instead of forcing a weak "this also applies to other browsers" bullet when no meaningful analog exists, the report names the boundary and stops there. Directions with genuine cross-engine reach still generalize as before; only the ones that don't extend get to opt out.
v1.0.0 — 2026-07-26
Initial versioned baseline.