📰 News

⚠️ Security warning: The X account VibeTrading_HKU, Virtuals project 101845, and token contract 0x640BDBF77b6447E8b7DB7894cED84BD1c40571f4 are not official Vibe-Trading assets. We have never launched or endorsed any token or memecoin. Do not buy, connect a wallet, or sign anything. Details.

  • 2026-07-21 🔧 Data-loader completeness + a reliability fix sweep: Partial market-data results now complete the missing symbols through the fallback chain and fail closed instead of silently shrinking the backtest universe (#689, closes #681, thanks @xkam7ar), and OKX bars use the history-candles endpoint with rate-limit retry for deep backfills (#644, thanks @tyj147454413-cmd). Plus a fix sweep: the MCP network guard accepts IPv6 / case-variant hosts (#750, thanks @Robin1987China), trade-journal parsers skip blank/NaN symbol rows (#749, thanks @Robin1987China), the Shadow Account skips the mined entry-hour gate on daily bars (#748, thanks @Robin1987China), and MiniMax regional API endpoints are selectable (#731, thanks @octo-patch).

  • 2026-07-20 🔀 Providers, MetaTrader 5, and a reliability sweep: Native Anthropic Messages API (optional [anthropic] extra, #695, thanks @jelech), SiliconFlow (#565, thanks @UNHNQ), and iFlytek Spark (#537, thanks @FenjuFu) join the provider roster, and a MetaTrader 5 (Exness) broker connector + mt5 forex/metal data source lands (broker connectors → 12, #481, thanks @StaniellG). Plus a provider-agnostic llm-vision OCR engine (#548, thanks @shadowinlife), an 80× signal-alignment vectorization (#698, thanks @shadowinlife), historical Binance USD-M funding/bracket data (#716, thanks @honginp), a swarm MCP-discovery cache (#704), and a reliability consolidation closing 13 SSE/session/CLI/swarm/scheduler issues (#584, thanks @xkam7ar). Correctness: options partial-close now honors the requested quantity instead of flattening the lot (#577), centralized provider credential resolution (#563), queued-cancel handling (#641), a frontend streaming-DOM race (#717, thanks @Marnie0415), and the connector CLI renderers (#726, thanks @nareshkps).

  • 2026-07-19 🔧 Real US/HK stock-news articles + MCP factor-analysis fix + a robustness pass: The stock-news tool now returns real Yahoo Finance articles (title/url/source/published/snippet) for US and HK tickers instead of related-instrument matches, still routed through the frozen IP-throttled client (#730, thanks @yxhuang). The MCP factor_analysis tool is realigned to the registered tool's real CSV contract, so calls no longer die on KeyError before running (#715, closes #635, thanks @Robin1987China). Plus a robustness pass: the whole Kimi K-series (k2/k3/…/for-coding) now auto-forces temperature=1 as the API requires (#701, thanks @sambazhu), and split_message, PDF page ranges, and trade-journal date filters all fail fast on degenerate or inverted input instead of hanging or silently returning nothing (#727#729, thanks @santhreal).

  • 2026-07-18 🔧 Binance crypto fallback + parallel-execution and correctness fixes: A Binance loader joins the crypto historical-data fallback chain (#643, thanks @tyj147454413-cmd), and the IBKR connector moves to a thread-local connection pool with snapshot quotes, fixing hangs under parallel agent runs (#636, thanks @MikeCer). Plus a correctness pass: factor analysis rejects non-positive n_groups, inverted period ranges and non-positive detection windows fail fast, an unnamed DatetimeIndex in the correlation matrix is handled, equity.csv nav/value column aliases are accepted, and empty A-share codes are no longer coerced to 000000.SZ (#709#714, thanks @santhreal). A correlation-rewiring stability factor joins the academic zoo (#705, thanks @ebujinovch), the fundamental zoo is whitelisted for factor analysis (#707, thanks @sambazhu), persisted run state is now fsync-durable (#645, thanks @tyj147454413-cmd), and the dev extra installs the documented Black/Ruff toolchain (#634, thanks @xkam7ar).

  • 2026-07-17 🧩 Correlation-regime skill + a broad backtest / data / live-safety correctness pass: a new correlation-regime detection skill (bundled skills → 88, #557, thanks @ebujinovch), a Longbridge runtime connection card (#569, thanks @fanfpy), and user-defined swarm presets loaded from ~/.vibe-trading (#570, thanks @darkknight4563). Plus hardening across the stack: silent-data-corruption fixes in the Futu / Tencent / CCXT / mootdx loaders, look-ahead-bias and strict-OOS guards in the factor bench and Shadow Account, live-trading safety (signed exposure caps, atomic daily order limits, consent-first mandate commits, fail-closed live state), and journal / QVeris-budget / swarm / CI-gate improvements (#552, thanks @xor-xe; much of the correctness work by @xkam7ar).

  • 2026-07-16 🔧 Dependency lock repaired + Windows settings save fix: the hash-verified runtime lock is regenerated so Docker's pip install --require-hashes resolves cleanly again, fixing the incompatible caio/pydantic-core/websockets pins (#564, closes #558, thanks @tianrking). Saving Agent LLM settings from the Web UI no longer returns HTTP 500 on Windows — the POSIX-only os.fchmod hardening is now platform-guarded, with a regression test for platforms without fchmod (#561, thanks @CRui5in).

  • 2026-07-15 🧮 Backtest correctness + Portfolio Studio core: A 10-PR convergence pass made rebalances causal and order-independent, charged terminal close costs, reported fill-derived turnover, enforced exposure caps, and kept validation output finite and strict (#530/#531/#532/#540). Charts now reuse the run's actual data source, repeatable market queries are no longer dropped, and .env loads refresh cached config (#535/#544/#554). Portfolio Studio #456 and config bug #541 are closed; provider fixes #528/#529 closed too. Thanks @YZY0108, @santhreal, @Robin1987China, @xkam7ar, @Marnie0415, and @marichu99.

  • 2026-07-14 🌉 Longbridge market data + modern MCP transport + provider reliability: Longbridge joins the historical-data fallback layer with key-gated credentials, date-window splitting, strict completeness checks, and an opt-in SDK dependency; four China-market flow tools gain verified Tushare fallbacks, and negative final equity no longer crashes backtest metrics. The MCP server now supports Streamable HTTP, write_file safely recovers aliased or missing path arguments, hypothesis updates reject unsupported fields, and Correlation requests are authenticated. NVIDIA NIM is now a first-class provider across Web Settings and both CLI onboarding paths, with a versioned compatibility User-Agent to address the reported 403; Web Settings now writes to the canonical ~/.vibe-trading/.env, migrates legacy configuration, and reports permission failures clearly, fixing the DeepSeek save-time 500 (#534, closes #516/#524; #528/#529). Thanks @fanfpy, @asahikiko, @santhreal, @sTunnaSu, @abhishekjaisinghani, @huangcheng, @ShiroKSH, @Meru143, @DIEGOD79, and @not-knope for the code, reports, and diagnosis.

  • 2026-07-13 🔒 Security hardening: all 10 external-audit findings closed + contributor batch: every finding from the 2026-07-10 external security audit (issue #476, discussion #468) is now addressed on main — Docker multi-stage rebuild with digest-pinned images, an AST-hardened backtest sandbox blocking network/subprocess/eval/os.environ/unsafe-open (including inside nested function bodies), short-lived single-use SSE auth tickets, hardened Compose (read-only rootfs, dropped capabilities, resource limits), auth + rate limiting on /correlation, security headers, hash-locked dependencies, and more. Also merged: opt-in TAP mode for Alpaca key isolation (#377, thanks @0xZKnw), realized portfolio turnover surfaced in backtest metrics (#478, thanks @Robin1987China), a Frazzini-Pedersen betting-against-beta academic factor (Alpha Zoo → 461, #480, thanks @YogeshModi24), a look-ahead-bias fix across all 5 portfolio optimizers (#487, thanks @YZY0108), and two preflight/provider-config fixes (#479/#484, closes #477/#482, thanks @ananaymital/@Bortlesboat).

  • 2026-07-12 🧪 Strategy Development Manager + contributor fix batch: the new strategy-dev-manager skill (#87) turns academic papers and broker research into registered factors/strategies with a persistent artifact store and automated IC/Sharpe decay monitoring — sdm_register / sdm_status / sdm_decay_scan drive an active → monitoring → decayed → disabled lifecycle over ~/.vibe-trading/ (#457, closes #455, thanks @shadowinlife). Also merged: the Correlation tab accepts bare tickers (AAPL,SPY) and walks the full loader fallback chain (#472, closes #471, thanks @yxhuang), the local loader honors requested intervals via OHLCV resampling (#467, thanks @Shizoqua), Binance USD-M perpetual history lands with explicit BTC-USDT-PERP routing + execution/mark price separation as the first #462 slice (#470, thanks @honginp), FastMCP transport imports now work across both module layouts (#469, thanks @roberttidball), and Requesty is available as an OpenAI-compatible LLM gateway provider (#474, thanks @Thibaultjaigu).

  • 2026-07-11 🚀 v0.1.11 released (pip install -U vibe-trading-ai): rolls up three weeks since 0.1.10 — first-class Indian equity (NSE/BSE) backtesting, the PIT-safe fundamental factor layer (Alpha Zoo → 460), the 16-adapter IM channel runtime, end-to-end scheduled research, optional QVeris premium data, and today's contributor batch: a turnover-aware optimizer (#466, thanks @Robin1987China), an analyze_image vision tool + NapCat DM pairing + the IM-media read fix (#464/#463/#465, thanks @fei-moss), Longbridge Decimal serialization (#459, thanks @fanfpy), and packaged-manifest count guards (#461, thanks @asahikiko). Full details: CHANGELOG · release notes.

  • 2026-07-10 🇮🇳 Indian equity (NSE/BSE) support + centralized env config: a dedicated IndiaEquityEngine lands — T+1 delivery, circuit bands, and a config-driven STT/stamp/exchange/SEBI/GST cost stack — with .NS/.BO symbol routing, an opt-in read-only Shoonya/Dhan data bridge, and 255 alpha101/qlib158 factors opted into the new equity_in universe (#305, thanks @muku314115). Environment variables now flow through a single Pydantic EnvConfig schema with an AST-based CI gate against future os.getenv sprawl (#440, closes #438, thanks @shadowinlife). Also: a second-confirmation dialog before committing a real trading mandate plus unified error toasts (#453, thanks @wison1717-maker), scheduled-research route tests (#452, thanks @Robin1987China), and GLM thinking models no longer lose their reasoning stream on the zhipu provider (#458).

  • 2026-07-09 🧯 Docker startup unblocked + provider/CLI contributor batch: Docker/server startup no longer crashes when FastAPI route iteration sees an included-router-like entry without path (#450, thanks @Penn-Live). We also landed the queued quick-win contributor fixes: loader fetch() signatures now match the protocol across OKX / Tushare / yfinance (#437, thanks @shadowinlife), the CLI resume prompt preserves the first user message (#448, closes #447, thanks @morluto), Codex OAuth defaults to openai-codex/gpt-5.4 (#446, thanks @morluto), Kimi for Coding is available as a distinct provider (#435, thanks @yxhuang), opencode provider mappings are wired (#444, thanks @imsankz), and Tushare reference code fences now say python instead of pyhton (#449, thanks @flash1234pku). Validation included focused server/CLI/provider/loader tests plus a Docker build and /health smoke.

  • 2026-07-08 💎 Fundamental factor layer (Phase 1) + optional QVeris premium data + maintainer day: PIT-safe SEC fundamentals now flow into daily factor panels — fund:* panel columns, filed-date anchoring with restatement and YTD-frame protection, and 4 new quality/value factors (registry now 460 alphas). Data routing gains an optional premium track: the 18 free sources stay the default, while QVeris unlocks 63+ providers via Settings → QVeris or vibe-trading data mode paid (see the QVeris section below). Also: api_server modularization completed (1,103 → 371 lines, #424 closing #331, thanks @shadowinlife), backtest validation.json no longer requires a pre-existing artifacts dir (#429, thanks @isaveall), clearer --swarm-run errors (#428, thanks @isaveall), and we reverted the governance stack that broke session chats (#433, thanks @yxhuang for the precise diagnosis).

  • 2026-07-07Contributor PR batch: merged the queued contributor work for IM channel timeout configuration (#413, thanks @SyntaxSawdust), Alpha Library social previews and the beginner tutorial (#396, #393, thanks @kadaliao), value-investing skills / tools / committee presets (#407, thanks @sambazhu), zero-sized order-field handling in trading_place_order (#417, thanks @irfanallana-oss), and timezone-aware UTC timestamps across session/API paths (#397, thanks @mustafakamal88).

  • 2026-07-06 🧭 Preflight hardening, API slices, and CN search fallback: provider preflight no longer follows redirects (#404, closes #402, thanks @SyntaxSawdust), the remaining API routes moved into focused modules (#387, superseding #383-#386, thanks @shadowinlife), and CN web-search fallbacks now include Alibaba Cloud IQS (#408, thanks @sambazhu). Maintainer cleanup added no-network fallback tests and EOF whitespace cleanup (fbac74f); main CI is green (run 28780619018).

  • 2026-07-05Contributor PR queue closed + Windows baseline green: merged the four non-draft PRs selected for today's maintainer pass. A-share mootdx batch pulls now let KeyboardInterrupt / SystemExit propagate instead of being swallowed by a bare except (#399, closes #398, thanks @shadowinlife). The Settings route slice and patched dependency floors are now merged under their original contributor PRs (#382, #390, thanks @shadowinlife and @aeonframework). Windows baseline compatibility now isolates loader caches, makes OAuth cache assertions platform-aware, skips one fork-only mock test on Windows, and bypasses proxies for MCP loopback fixtures (#401, thanks @Elfsa-Miranda). Validation: 4701 passed, 47 skipped.

  • 2026-07-04 🧩 API route slices, tutorial docs, and dependency floors: IM channel and Settings routes moved out of api_server.py into src/api/channels_routes.py and src/api/settings_routes.py, continuing the narrow #331 modularization path from contributor work (#379, #382, thanks @shadowinlife). The wiki gained a Chinese beginner tutorial for non-finance readers (#393, thanks @kadaliao), and dependency floors now keep Pillow / LangChain / LangGraph on the installable patched track (#390, thanks @aeonframework).

  • 2026-07-04 🧹 UTC timestamp cleanup for session and API paths: tightened the #395 timestamp fix so session, goal, channel, and API timestamps now emit timezone-aware UTC values in explicit ISO form.

  • 2026-07-03 🛡️ Robinhood MCP refresh + API modularization + SSRF guard: Robinhood Agentic Trading now uses the current MCP tool names across generic reads, live-runner plumbing, default read-only seeds, and mandate-gate tests, while interactive startup honors the same .env search order as the provider loader (~/.vibe-trading/.envagent/.env$CWD/.env) (#391, closes #381 and #380). System routes (/health, /correlation, /system/shutdown, /skills, /api) moved into src/api/system_routes.py as the next narrow API modularization slice (#378, thanks @shadowinlife). Channel media SSRF defenses now reject CGNAT/mesh/non-global targets and QQ media redirects-to-internal before fetching (#389, thanks @hobostay).

  • 2026-07-02Factor acceleration + safer runtime boundaries: hot rolling factor operators now use bottleneck/NumPy fast paths, alpha bench parallelism avoids repeated large-panel worker payloads, and base equity math has regression coverage (#376, closes #339, original work from #342 by @shadowinlife). Upload and Shadow report routes moved out of the monolithic api_server.py as the first narrow API modularization slice while #331 stays open (#375, based on #358, thanks @shadowinlife). Generated backtests now inherit only an allowlisted subprocess environment instead of the parent secrets surface (#374, closes #332), and IM channels gained /new session reset plus case-insensitive pairing commands (#372, closes #371, thanks @shadowinlife).

  • 2026-07-01 🧹 Security polish + tracker cleanup: tightened API/Docker/frontend dev defaults, stabilized Settings channel and zh-CN edges, cleared frontend dependency/CSP alerts, and closed stale WhatsApp + paper-trading tracker items (#338, #351, #349, #365, #367, #350, #335, #283).

  • 2026-06-30 💬 IM channel runtime for research delivery: Vibe-Trading can now attach the same agent session runtime to 16 built-in message adapters — WebSocket, Telegram, Slack, Discord, Matrix, WhatsApp, Signal, QQ/NapCat, WeChat/WeCom, Feishu/Lark, DingTalk, Teams, email, and Mochat. CLI (vibe-trading channels status/start/stop/login/pairing), REST (/channels/status, /channels/start, /channels/stop, /channels/pairing/command), and the Web UI Settings panel expose status, recovery hints, start/stop, and sender pairing; SDK-backed adapters stay behind extras such as vibe-trading-ai[telegram] or vibe-trading-ai[channels] (#341).

  • 2026-06-29 🛡️ Live advisory safety + Trading 212 read-only connector + Windows/Gemini fixes: live order guards now have an opt-in, broker-agnostic PreTradeAdvisoryInterface that records advisory reviews without bypassing the mandate gate, kill switch, or audit trail (#328, closes #317, thanks @shadowinlife). Trading 212 joins the connector layer with read-only account, positions, orders, history, and instrument-metadata support; place_order / cancel_order still hard-refuse until a structural paper/live boundary exists (#321, closes #309, thanks @mvanhorn). Windows startup avoids the pandas 3.0 Timestamp crash via the <3.0.0 constraint (#329, closes #324, thanks @hannibal-lee); Gemini thought_signature dict-history replay was verified/fixed on main (#318); .US financial statements now route to SEC EDGAR instead of Eastmoney (#325); and the Alpha Library landing page got cache/date/selector/noscript/DNS-prefetch hardening while heavier CSP and social-card follow-ups stay tracked (#323).

  • 2026-06-28 🧰 Cross-platform setup/dev + runtime and file-tool hardening: vibe-trading setup and vibe-trading dev now handle Windows TypeScript builds, launch the backend from the right cwd, use the Vite 5899 port, and shut child processes down cleanly (#292, thanks @digger-yu). Runtime status polling now degrades instead of crashing (#322); MCP OAuth cache keys are sanitized (#313); OpenAI defaults and Robinhood agent.json validation were tightened (#319, #320, thanks @mvanhorn); and file tools got isolated read/write roots plus broader sandbox tests (#299, thanks @skloxo).

  • 2026-06-27 🧯 Content-filter resilience + Shadow Account feature contract cleanup: event-driven and swarm runs now skip individual LLM content-moderation hits, warn in run cards when filter rates are high, and recognize Gemini safety finish reasons instead of aborting an entire analysis (#308, closes #307, thanks @shadowinlife). Shadow Account extraction/codegen now share one PRICE_FEATURES contract and keep four-decimal return bounds, preventing rule/codegen drift and precision loss on prior_5d_return (#316, thanks @Robin1987China).

  • 2026-06-26 🎯 Shadow Account conditional entry + tushare ETF/index/HK routing: extracted Shadow Account rules now carry RSI / prior-return bounds, so the generated SignalEngine enters on real conditions (RSI in range, prior-return in range) instead of blindly replaying the holding cadence (#314, follows #302, thanks @Robin1987China). The tushare loader also routes ETF/LOF → fund_daily(), indices → index_daily(), and HK equities → hk_daily() instead of always calling daily() (which silently returns empty for non-stocks), with per-symbol empty-result + partial-fetch warnings (#315, closes #310, thanks @shadowinlife).

  • 2026-06-25 🧪 Strict validation JSON + calmer agent context: standalone backtest validation now normalizes nested NaN / Infinity values before writing artifacts/validation.json or CLI stdout, so strict JSON parsers no longer choke on validation payloads (#306, thanks @gyx09212214-prog). The agent prompt also derives the current data-source count from the loader registry, and _microcompact() now waits for real token pressure instead of clearing older tool results during short runs (#296, closes #282, thanks @MarkfuGod).

  • 2026-06-24 🎯 Shadow Account price context + reactive Chinese UI + LAN auth fix: Shadow Account rule extraction now sees PIT-safe entry context — entry_rsi14 and prior_5d_return fetched through the loader registry as of buy_dt, with graceful offline/no-data degradation (#302, follows #295, thanks @Robin1987China). The main Web UI panels now use reactive English / zh-CN translations across charts, chat, Alpha Library, Correlation, and Run Detail (#301, thanks @skloxo). Remote same-origin Web UI deployments with API_AUTH_KEY can post and upload again after the CSRF hardening, while mismatched cross-site origins remain blocked (#304, thanks @Hinotoi-agent).

  • 2026-06-23 🛡️ Local API CSRF hardening: a malicious web page can no longer drive unsafe cross-site requests (POST/PUT/DELETE) against the loopback API — CORS blocks reading the response but not the side effect, so loopback dev-mode trust now applies the existing cross-site guard to unsafe methods before honoring it. Safe methods and local CLI / non-browser uploads are unaffected (#293, thanks @Hinotoi-agent).

  • 2026-06-22 🔧 Live-authorize OAuth fix + Alpha Zoo headline fix: connector authorize now holds the OAuth handshake open through a multi-minute broker sign-in (tunable via VIBE_LIVE_AUTHORIZE_TIMEOUT_SECONDS) and no longer spawns a competing callback server on retry, so the token actually persists (#281, closes #259, thanks @Robin1987China). The Alpha Zoo page no longer prints its alpha count twice (#287, closes #286, thanks @digger-yu). Scheduled research also picked up end-to-end usage docs (#288).

  • 2026-06-21Scheduled-research executor + Reports library + post-backtest attribution: scheduled research now runs end to end — a default-off background executor (VIBE_TRADING_ENABLE_SCHEDULER) fires due interval/cron jobs through the session runtime (#278, thanks @mvanhorn, closing #254). A new /reports Run Library page lists, searches, and filters report-worthy runs with links into Run Detail + Compare (#224, thanks @LemonCANDY42). And after every backtest the agent now runs layered attribution — trade-level winners/losers, beta regression, market-regime analysis, and a Monte Carlo permutation test, gated by data availability and routing (#280, thanks @shadowinlife).

  • 2026-06-20 🔬 Research Autopilot loop closes (Phase 3) + loader OHLC integrity guard + 4 academic alphas: Research Autopilot now runs hypothesis → signal-engine → backtest end to end — scaffold_signal_engine writes a contract-correct engine and link_autopilot_backtest feeds run metrics back to the hypothesis (68 tools) (#267). A structural OHLC sanity check drops dirty bars (high < low, non-positive prices, bad bracketing) centrally at the loader boundary, guarding every data source (#274, thanks @Shizoqua). And the academic alpha family grows 6 → 10 — Jegadeesh reversal, George-Hwang 52-week-high, Amihud illiquidity, Harvey-Siddique skew (456 factors) (#277, thanks @Robin1987China).

  • 2026-06-19 🚀 v0.1.10 — Global data layer: market-data sources grow 10 → 18 (free Eastmoney / Sina / Stooq / Yahoo + key-gated Finnhub / Alpha Vantage / Tiingo / FMP, ban-risk fallback) plus 18 read-only data tools (fund flow, dragon-tiger, northbound, margin, block trades, SEC EDGAR + XBRL, financials, options chains, full-market screening…) across A-share / US / HK, all over MCP. Also bundles everything since 0.1.9 — 10 broker connectors, alpha compare, the provider-reliability overhaul, and the opt-in data cache. pip install -U vibe-trading-ai

  • 2026-06-18 🔬 Research Autopilot Phase 1 + a local Data Bridge loader, + a Discord security notice: new run_research_autopilot + generate_backtest_config wire Hypothesis → Research Goal → backtest end to end (now 50 tools), and a local loader reads OHLCV straight from your own CSV / Parquet / DuckDB files (#260, #252, thanks @Robin1987China), alongside DeepSeek DSML tool-call parsing and an identifier-containment hardening wave. ⚠️ Security: the old community Discord invite now points to a server we don't control running a fake Collab.Land wallet-"verification" phishing scam — removed everywhere; the only official Discord is the HKUDS server (discord.gg/6TdQnT5xcF), and we'll never ask you to connect a wallet.

  • 2026-06-17 🧩 Install compatibility + Opus/Kimi provider fixes: Baseline pip install vibe-trading-ai no longer pulls the optional pyharmonics / ta dependency chain; harmonic detection now lives behind vibe-trading-ai[harmonic] while the bundled detector remains available (#250, closes #249). The agent loop also avoids assistant-prefill handoff messages rejected by Opus 4.8+, and Kimi/Moonshot can override the client User-Agent with MOONSHOT_USER_AGENT (#248, closes #246 and #204); follow-up tests now directly cover background-result and auto-compact handoff paths (#251).

  • 2026-06-16 🛡️ Security/API hardening + GLM/Zhipu alias: Settings writes require auth when configured (#245); API shell-capable tools require explicit VIBE_TRADING_ENABLE_SHELL_TOOLS=1 opt-in (#243); local shutdown requires auth when an API key is configured (#241); and untrusted loopback-looking hosts are rejected instead of treated as local (#242). Runtime edges also got cleaned up: Web chat syncs completed attempts (#236), run cards emit strict JSON for non-finite metrics (#238), malformed RSSHUB_TIMEOUT_S / RSSHUB_FETCH_BUDGET_S falls back safely ([#240](https:/