- Fix several permissioning and secret handling bugs (commit permissions, host resolution for Postgres, SQL Server dynamic secrets, secret reference formatting, SSO seat limit check)
- Add new features: user notifications, gateway v2, Cribl audit‑log streaming, card‑declined alerts, and allow users to change email addresses
- Improve existing functionality: lockout error messages, Google OAuth enforcement, nightly release pattern, and update plan‑fetch logic