Skip to content

3.9.0

Release Date: September 2, 2026

This release ships the forge and forge-planning skill packages as installable Agent Plugins, bundles the Mosaic MCP server for design-system access, and completes the multi-phase effort to eliminate tfe_outputs remote-state coupling in Terraform modules — with a CI guardrail so it can't regress. The CLI adds plan-mode permission classification for saif commands and Agent Plugin auto-install/update via doctor fix, and Terraform defaults blob storage to private-endpoint isolation.


✨ New Features

Agent Plugins & MCP

  • Ship forge and forge-planning as installable Agent Plugins packages, bundling the Mosaic MCP server in the forge package (cafa0c53 | #1001, 25d84b2c | #1040)
  • cli - saif agent init registers and directly installs Forge Agent Plugins, now defaulting to a user-scoped install (c7cc1954 | #1012, 4f59d668 | #987)
  • cli - saif doctor fix detects and updates installed Agent Plugins (f03d7cf0 | #1034)
  • mosaic - bump Mosaic to v18 (e4f93a53 | #976)
  • mcp - upgrade to MCP 2026-07-28 with explicit conversation IDs (e0a940ac | #1024)

CLI

  • Classify saif commands as read-only/mutating and generate plan-mode permission rules from the classification (b6189973 | #977)
  • Scope pipeline logs to the job/step in a build URL (c3677a3d | #1107)
  • Show installed and latest versions in doctor results (2fb00883 | #1072)
  • Add --trace-id to otel traces and logs (745b21bf | #921)

Terraform

  • Default blob storage to a private endpoint with network isolation (c5810602 | #1037)
  • Grant Document Intelligence RBAC via an identity module flag (b80b35c3 | #1047)
  • Configure the Okta provider from an env-category variable set, and attach the existing Okta variable set to app workspaces via tfe-bootstrapper (a59e76fc | #845, aeda4776 | #1023)
  • Eliminate the residual okta_app tfe_outputs read, closing out the #845 migration (6a6b5685)
  • infra - add app-specific custom domain support to Front Door routes (f93a7fe3 | #929)

Governance & Templates

  • templates - add PlatformDev as a bootstrap additional_environments entry (832f5043 | #1031)
  • business-roles-corp - warn when manual_users is set in non-production (9938d4ad | #1110)
  • client - add TanStack Query (16bf191c | #964)

🔧 Enhancements

  • infra - eliminate all remaining tfe_outputs remote-state lookups (#845 Phase 1 — zero residuals) (b36c51e4 | #914)
  • cli - retire MCP guided-workflow prompts for shipped skills (41112865 | #1017)
  • Fix oversized skill descriptions and strip anti-triggers (20c3bd8c | #1068)

🐛 Bug Fixes

CLI

  • Exclude Smithy's native-duplicate MCP tools from the remote bridge (ab6fe358 | #1013)
  • Compare remote URLs semantically in AddRemoteAsync (ffd3f0b4 | #961)
  • Use -EncodedCommand for the detached self-update process (69879833 | #960)
  • Emit filter-field syntax in the traces explorer deep link (683c821f | #955)
  • Surface failed pipeline steps whose log lives on an ancestor record (f494e214 | #954)

Terraform

  • Avoid a depends_on cycle in saif-application-permissions (aebba880 | #1080)
  • Suppress role-assignment scope casing drift, adding replace_triggered_by hardening to the casing-drift-guarded assignments and covering the remaining KV secret readers (bc0e6387 | #1077, 0693106a | #1075)
  • Show available subdomain keys in the custom-subdomain check message (4289cd30 | #1046)
  • Grant storage Blob Data Contributor to the app registration service principal (55dd1673 | #1027)
  • Resolve the blob storage connection string from module output instead of a stale reference, and stop passing null network rule args to storageaccount (e3ec6838 | #1005, 83e71f49 | #1004)
  • saif-event-service - wrap fd_custom_domain_ids with nonsensitive() before iterating, and dedupe Front Door custom domain IDs to fix a prod deploy failure (c868898c, 3a53ff54 | #947)
  • tfe-bootstrapper-business-roles - stop attaching the Okta corp variable set to corp-tenant workspaces (05d7bc10 | #1108)

Templates

  • Remove the Okta provider/variables from the corp test-tools scaffold (5d23e80a | #1111)
  • Fix frontend pre-commit/pre-push hooks and unit test failures (1915147e | #1030)
  • Remove a stray infra/auth/external folder and refresh the blob storage docs (a7a0c9dc | #999)

Workflows & CI

  • Bump the pinned Microsoft.Extensions.AI package version to resolve a Smithy NU1605 restore failure (563750ad | #1097)

Other

  • oracle - escape Oracle connection strings via OracleConnectionStringBuilder so passwords containing ; no longer corrupt the connection string (07917c0f | #962)
  • ui - add body-scroll-padding (132359a6 | #956)
  • git - stop Directory.Packages.props showing as permanently modified, and renormalize its line endings per .gitattributes (bb04dc47 | #953, c07ffc64 | #935, 6f406999)

📚 Documentation

Troubleshooting Articles

New articles cover: null function_app_service_plan_id (#1109), a tainted-role-assignment guide and preferring the saif CLI for pipeline log triage (#1104), storage account network_rules null errors (#1093), blob storage 403 AuthorizationPermissionMismatch (#1091), saif publish pipeline creation and remote URL issues (#1090), a function app deploy invalid-version warning (#1089), AzureCli Authorizer az not found (#1088), an application_permissions inconsistent final plan (#1086), and system/coding-agent Azure DevOps MCP setup (#1084) — with a companion fix correcting the Azure federated identity setup for the coding agent and code-review OIDC (#1087).

Guides & Reference

  • platform-typespec - add reference documentation for @saif/platform-typespec (5aa532c9 | #1063)
  • tutorials - close the local-to-deployed gap in onboarding (fa7dd92a | #1041)
  • Add an on-premise API proxy strangler plan and a YARP auth anti-corruption layer one-pager for the Guidewire Cloud migration (321dde84 | #972, a32e7ae9 | #915)
  • Correct the custom subdomains guide for the cloud-foundations flow (f460ffd0 | #959)
  • auth - document the client-credentials fallback for when no incoming token is present (44e778a0 | #911)
  • Warn against creating a duplicate business roles repo (7a4bc425 | #1106)

Cleanup

  • Retire shipped/stale planning docs, distilling durable reference content, and archive the forge-v1-to-v2 migration guide (bf5e47ab | #990, 12217200 | #1019)
  • Remove the stale platform roadmap page and its remaining bullets (2b8d5556, e3f1067f)
  • storage-account - hardcode contributor_group_id instead of a data source lookup (ca2aa93d | #1009)

📦 Dependencies

Routine dependency maintenance via Dependabot: 34 PRs across NuGet and npm/yarn workspaces, including notable manual bumps of @typespec/http-server-csharp, Verify.XunitV3, postcss, fast-uri, and @opentelemetry/auto-instrumentations-web. See the full commit range for the complete list.


🔄 Breaking Changes

None in this release ✅


📋 Additional Notes

  • Total commits: 133
  • Files changed: 1156
  • Contributors: Brian Sheridan, Copilot, dependabot[bot], Emmitt Johnson, Gabe Higginbotham[C], Jason Coria Corona Yue, jasyue

Support

  • 📧 Teams Support Channel: Support