Release notes · newest first

What's new in the toolkits.

Highlights for every ShipIt toolkit. Each release keeps full C# source and leaves your project data untouched, and each package ships its complete engineering changelog as CHANGELOG.md. Pre-release versions are marked; they are not on the Asset Store yet.

Supabase Toolkit
Sep 26, 2026

v1.52.1 — first-run repair, security and WebGL hardening

A correctness release for the path every new buyer takes first, plus the WebGL rules written into the package.

  • Onboarding: the "Open Setup Wizard" button did nothing on 20 tabs; it now navigates, and Reset setup really reopens onboarding.
  • WebGL: UploadFileAsync fails fast with a pointer to the byte-based uploads, resumable uploads default to 1 MB chunks, and the realtime socket survives messages racing shutdown.
  • Security: the migrations executor is service-role only, 16 findings in shipped SQL are fixed, and a build guard now finds service-role keys anywhere in the project.
  • Safety: Send push and Clear queue confirm first, Live Ops sends refuse a double click, and destructive buttons look destructive.
  • MCP server: the bundled pack catalog shipped unparseable and four packs behind; it now lists all 38 packs, and the server refuses to start on a broken catalog.
  • Proof: an IL2CPP player built with High stripping runs, with 327 types and 39 serializable DTOs intact. The v1.52.0 suite passed 267 EditMode tests on Unity 6000.3.11f1 and 2022.3.55f1, and 3 PlayMode tests on 6000.3.11f1.
No API change.
Re-import, then re-run
installed packs for the
SQL fixes.
AWS Toolkit
Sep 26, 2026 · pre-release

v0.36.0 — Cognito auth edge cases

Authenticator-app MFA setup (AssociateSoftwareTokenAsync, VerifySoftwareTokenAsync, SetSoftwareTokenMfaPreferredAsync), required attributes for NEW_PASSWORD_REQUIRED pools, a Hosted UI logout URL, and a pure-C# Hosted UI popup for WebGL with a 15-minute limit on pending sign-ins.

  • Fixed: SECRET_HASH on the SRP start for secret-bearing app clients, the refresh-token username hash, and unknown challenges now raise AwsAuthChallengeException with the session intact.
  • Fixed: the package now declares the Audio modules its audio loader uses, so it compiles in projects that turn them off.
  • 423 EditMode + 2 PlayMode tests pass on Unity 6000.3.11f1 (Sep 30), and the Unity 2022.3 floor is verified in a clean project.
  • Not released: the Asset Store listing is not live yet.
Breaking: change
using ShipIt.Aws.GameSystems;
to
using ShipIt.Aws.Features;
License Toolkit
Sep 26, 2026 · pre-release

v0.4.0 — compliance gates

The release gate learns severity: a fail-on level and a minimum quality score, per-entry quality scores with the deductions shown, a VEX sidecar next to the SBOMs, and a Vetting tab that grades each entry Pass, Review or Block.

  • A detect-only probe reports the Unity 6 global package cache without ever opening it.
  • Everything new is opt-in; nothing changes for existing projects until you turn it on.
  • 156 EditMode + 1 PlayMode tests pass on Unity 2022.3.62f1 and 6000.3.11f1 (Sep 30), and the UPM package installs into a clean project with its self-test passing.

Scores are triage heuristics, not legal verdicts. Informational only — not legal advice.

Firebase Toolkit
Sep 20, 2026 · pre-release

v0.23.0 — agent-native surfaces and the Unity 6.3 floor

Agent context now ships in the package: llms.txt and a capability manifest generated from the shipped source, a headless command dispatcher, three installable agent skills and a local, socket-free MCP bridge. Agents read the real API surface instead of the official SDK this package does not use.

  • Minimum Unity is now 6.3 LTS (6000.3); the TextMeshPro dependency moved to com.unity.ugui 2.x.
  • An empty Storage bucket now derives <project-id>.firebasestorage.app, and HTTP 402 plan failures explain the Blaze requirement.
  • 776 EditMode + 17 PlayMode tests pass on Unity 6000.3.11f1; the WebGL build boots in headless Chromium and the Windows IL2CPP build is clean.
Needs Unity 6.3 LTS
(6000.3) or newer.
AWS Toolkit
Sep 20, 2026

v0.35.0 — agent skills installer

Tools → ShipIt → AWS Toolkit → Install Agent Skills copies the five bundled task skills into the project's .claude/skills/ folder so coding agents auto-discover them — source resolution covers UPM/embedded installs, the .unitypackage import root and renamed import folders, and re-running refreshes the copies.

  • Five tests cover resolution, discovery, copy/overwrite and target validation.
  • 389 EditMode + 2 PlayMode tests pass, zero warnings, gate green.
AWS Toolkit
Sep 20, 2026

v0.34.0 — agent-ready toolkit

The toolkit now ships an agent bundle — llms.txt, a package agent guide and five task skills (setup, auth, WebGL, data, troubleshooting) — and machine-readable diagnostics: doctor findings and smoke reports come as JSON as well as Markdown. With Unity's Pipeline package (Unity 6+), eleven aws_* Unity CLI commands let an agent or CI run the doctor, deploy the stack, import outputs, verify the backend, generate models and repositories, provision tables, render IAM policies, estimate cost, check the release gate and export the store artifact — every mutation gated behind confirm=true with dry_run previews.

  • The command assembly is version-guarded on com.unity.pipeline, so the Unity 2022.3 floor and the runtime player are untouched.
  • The exported .unitypackage now ships the documentation set and the agent bundle under Documentation/; tests and package.json stay excluded.
  • 384 EditMode + 2 PlayMode tests pass, zero warnings, gate green.
AWS Toolkit
Sep 10, 2026

v0.33.0 — player economy

aws.Game.Economy transacts balances plus an append-only ledger in one TransactWriteItems call: grants, spends and transfers commit atomically, with idempotency keys so replays cannot double-credit, insufficient_funds rejections carrying the current balance, and TTL-retained ledger history. Player IAM rows are scoped per caller with LeadingKeys; the admin policy covers both tables.

  • Six tests cover grant shape, insufficient funds, duplicate replay, the four-item transfer, ledger queries and validation.
  • 367 EditMode + 2 PlayMode tests pass, zero warnings, gate green.
AWS Toolkit
Sep 10, 2026

v0.32.0 — transactional conditional updates

The data layer now executes conditional SET/ADD/REMOVE updates inside transactions (DynamoWrite.Update), with per-item conditions on puts and deletes, and one shared #name/:value namespace per item — the API requirement, guaranteed by construction. Cancellations surface structured per-item reasons via DynamoTransactionCanceledException.FailedAt(index), so "insufficient funds" is distinguishable from "duplicate idempotency key" without parsing messages.

  • Foundation for the economy/inventory system (conditional balances + idempotent ledger in one transaction).
  • BatchWriteItem now rejects update writes with a pointer to TransactWriteAsync instead of silently emitting a delete.
  • 316 EditMode + 2 PlayMode tests pass, zero warnings.
AWS Toolkit
Sep 10, 2026

v0.31.0 — server-authoritative scoring, actually reachable

The docs promised the Packs tab shipped the game-submit-score Lambda; now it does. Copy game-submit-score handler puts the Node.js 22+ source on the clipboard and Save handler… writes it to disk for console/SAM/CDK deployment — deploy with TABLE_NAME=GameLeaderboards, then tick the toggle to strip direct leaderboard writes from the generated player policy.

  • Closes a documentation/UX gap: the template existed in code but had no UI.
  • 311 EditMode + 2 PlayMode tests pass, zero warnings.
AWS Toolkit
Sep 10, 2026

v0.30.0 — on-device verification runner

The live smoke suite now runs where the editor cannot: drop AwsSmokeRunner on a bootstrap-scene GameObject, build for Android/iOS/WebGL, and it runs automatically, shows a scrollable pass/fail overlay with a Copy report button, and writes the same Markdown artifact to persistentDataPath. A device pass needs no debugger, and a demo-mode run is loudly flagged because it is not live evidence.

  • The device matrix documents the on-device path and how to retrieve the report per platform.
  • Editor and device passes now produce identical artifacts via SmokeReportWriter.
  • 311 EditMode + 2 PlayMode tests pass, zero warnings.
AWS Toolkit
Sep 10, 2026

v0.29.0 — UI Toolkit panels

A modern runtime panel kit: AwsAuthPanelUIToolkit and AwsLeaderboardPanelUIToolkit ship UXML + USS and mirror the uGUI behaviour — binding to the client whenever it initializes or is replaced, MFA and forced-password continuation on Confirm, leaderboard waiting for sign-in and refreshing automatically, busy and error states — with a designed dark theme. No TextMeshPro dependency was added: UI Toolkit renders its own text, so imports stay lean.

  • Each USS is self-contained; Panels need a PanelSettings with a theme style sheet, which the new docs page walks through.
  • EditMode tests load both UXMLs and resolve every documented element name.
  • 308 EditMode + 2 PlayMode tests pass, zero warnings.
AWS Toolkit
Sep 10, 2026

v0.28.0 — Pinpoint push registration

Re-engage players with mobile push. aws.Pinpoint registers device tokens (GCM, APNS, APNS_SANDBOX, ADM, BAIDU) as Pinpoint endpoints over the signed mobiletargeting REST API, flips opt-out while preserving the rest of the endpoint, and deletes it on sign-out. The token itself comes from your Firebase/APNs layer; the toolkit carries it to AWS with the player's temporary credentials.

  • Set PinpointApplicationId and grant the Identity Pool role mobiletargeting:UpdateEndpoint on the app.
  • WebGL has no device token, so push is a mobile/desktop feature — the platform matrix says so plainly.
  • Nine tests cover signed wire shape, channel mapping, read-back, opt-out preservation and errors: 306 EditMode + 2 PlayMode pass.
AWS Toolkit
Sep 10, 2026

v0.27.0 — live verification artifacts

Live verification becomes a repeatable pass instead of a vibe. A device-matrix checklist documents how to run the Connection-tab smoke suite per platform, the rows to fill and the manual checks the suite cannot do (SRP on a hardened pool, WebGL CORS from the real origin, forced-retry survival, resumable multipart after a kill, realtime socket recovery, hosted-UI deep links, custom-auth OTP). Each run now produces a Markdown smoke report — platform, OS, device model, Unity/app versions, region and every step's result — with Copy/Save buttons in the Connection tab.

  • One artifact per device per release candidate; a failure blocks the release or is waived with a reason.
  • 297 EditMode + 2 PlayMode tests pass, including eight tests for the report artifact.
AWS Toolkit
Sep 10, 2026

v0.26.0 — realtime WebSockets

Presence, chat, lobbies and live leaderboards over API Gateway: aws.Realtime connects with IAM-presigned wss:// URLs (browsers cannot set handshake headers — SigV4 query parameters are the workaround), queues sends while offline, reconnects with bounded exponential backoff and sends configurable heartbeats ahead of API Gateway's 10-minute idle timeout.

  • Routes stay application-defined: the client carries JSON strings, not a schema.
  • ClientWebSocket on editor/desktop/mobile; a bundled browser bridge for WebGL.
  • Eleven tests cover dispatch, offline queue flush, reconnect give-up, heartbeats and presigned-URL shape: 289 EditMode + 2 PlayMode pass.
AWS Toolkit
Sep 10, 2026

v0.25.0 — one-click deploy from the editor

Setup step 2 can now run the backend deploy itself. With the AWS CLI on PATH, Deploy from the editor runs aws cloudformation deploy with the bundled template — region, CORS origin, smoke-test auto-confirm and server-authoritative scoring as fields — streams the output into the window log, and Import stack outputs writes the five values straight into AwsSettings. Credentials stay with the CLI (profiles/SSO), so no admin keys touch the project; the template + console route remains as the fallback.

  • The editor stays responsive during the minutes-long deploy; output drains on the main thread.
  • Ten tests cover argument quoting, output parsing (incl. CLI noise), output→settings mapping and missing-CLI handling.
  • 278 EditMode + 2 PlayMode tests pass, zero warnings.
AWS Toolkit
Sep 10, 2026

v0.24.0 — cost awareness

A built-in estimator turns usage assumptions — MAU, DAU, per-player reads and writes, Lambda calls, S3 storage and egress — into a monthly per-service breakdown, with every rate editable because AWS list prices drift. The same estimator runs inline on the Packs tab.

  • The worked example lands at ~$128/month for 10k DAU — and Cognito MAU dominates the bill, not the game data.
  • Documentation~/costs.md lists the defaults that keep costs small: on-demand DynamoDB, TTL retention, projections, offline coalescing, presigned downloads.
  • Ten arithmetic tests cover unit scaling, the Lambda free tier and custom price sheets: 268 EditMode + 2 PlayMode pass.
AWS Toolkit
Sep 10, 2026

v0.23.0 — phone OTP, security and verification

Passwordless sign-in is now first class: SignInWithCustomAuthAsync + RespondToCustomChallengeAsync drive Cognito's CUSTOM_AUTH flow, and custom-auth-otp.yaml ships the three challenge Lambdas in production shape — TTL code table, constant-time comparison, attempt burn-out and a marked delivery stub for your SMS provider.

  • Real threat model in SECURITY.md: credential flow, protections, explicit non-protections and a pre-ship checklist.
  • Published verification report: offline suite counts per release, external reference-vector provenance, and the not-yet-live-verified list.
  • The Doctor tab links straight to the hosted troubleshooting guide.
  • 257 EditMode + 2 PlayMode tests pass, zero warnings.
AWS Toolkit
Sep 10, 2026

v0.22.0 — richer offline sync

The offline queue becomes a feature. Replay now takes a policy: stop on the first failure (unchanged default) or skip permanent failures into a persisted dead-letter list — with per-table overrides so independent entities keep flowing while economy writes stay strictly ordered. Transport failures still stop the pass; only real failures are dead-lettered, with their error text.

  • Key-aware enqueues coalesce repeated offline edits to one net write — twenty edits become one PUT.
  • RetryFailed() / ClearFailed() manage dead letters; the journal format is v2 and still reads v1.
  • A live queue inspector in the Diagnostics tab shows pending and failed mutations while the game runs.
  • Tests: 254 EditMode + 2 PlayMode pass.
AWS Toolkit
Sep 10, 2026

v0.21.0 — S3 progress and resumable multipart

Uploads and downloads now report 0..1 progress on every platform — pumped from the player loop, so WebGL works too. UploadLargeResumableAsync persists a multipart upload under a caller-chosen resume ID; after a crash the next call reconciles with ListParts, seeks past the parts the server already has and continues at the first missing one. AbortLargeUploadAsync cancels an interrupted upload and releases its storage.

  • Failed resumable attempts keep their state instead of aborting server-side.
  • Per-part progress rolls up into one monotonic whole-file progress stream.
  • Tests cover resume-without-reupload, expired-upload restart, abort and ListParts pagination: 245 EditMode + 2 PlayMode pass.
AWS Toolkit
Sep 10, 2026

v0.20.0 — try it with no AWS account

Demo mode installs an in-memory backend behind the existing transport: Cognito sign-up and sign-in, Identity Pool credentials, all four game tables, analytics and PartiQL run with no AWS account and no network. The tables are seeded with a small leaderboard and a double_xp flag, so the demo scene is playable immediately — and the toolkit's own condition expressions are evaluated for real, so best-wins scoring and save concurrency still hold.

  • Editor and development builds only; release players ignore it and the Doctor warns while it is on.
  • S3 and Lambda report a clear "not implemented in demo mode" instead of reaching the network.
  • End-to-end tests drive the real services through the demo transport: 237 EditMode + 2 PlayMode tests pass.
AWS Toolkit
Sep 10, 2026

v0.19.0 — typed repository generation

The Generator tab now emits a typed repository beside the model: key-typed get/delete, put with an optional condition, and a partition-key query. Key names and scalar types come from the live table's DescribeTable schema — numeric keys become long, binary keys byte[] — so gameplay code stops spelling table and attribute names.

  • DescribeTableAsync exposes the key schema; TableExistsAsync delegates to it.
  • Models gain HASH/RANGE annotations from live metadata.
  • Reference tests cover the parser and the emitter: 230 EditMode + 2 PlayMode tests pass.
AWS Toolkit
Sep 10, 2026

v0.18.0 — guided setup, lifecycle hardening, leaner imports

The AWS toolkit gets a guided first run: a Setup tab walks create asset → deploy stack → paste outputs → verify → create game tables → play the demo, each step checking itself off. Runtime UI rebinds whenever the client is initialized or replaced, the leaderboard panel waits for sign-in and loads automatically, and buffered analytics flush on application pause and quit.

  • DynamoDB Query/Scan gained ProjectionExpression support; cloud-save slot listings no longer transfer save payloads.
  • A PlayMode suite now covers the drop-in panels: 216 EditMode + 2 PlayMode tests pass with zero warnings.
  • CI jobs skip cleanly with a warning until Unity license secrets are configured.
  • Dropped the unused TextMeshPro dependency — imports stay lean.

Full history lives in the package changelog.

AWS Toolkit
Aug 31, 2026

v0.17.0 — compiling, tested, wire formats corrected

The first release in which the EditMode suite executed, which surfaced and fixed wire-format, signing and serialization defects across Cognito, DynamoDB, S3 and Lambda: inverted expression attribute names, auth parameter maps, SECRET_HASH, path-style S3 signing, Lambda URL encoding, and the event-stream CRC (IEEE, not CRC-32C) — every path pinned against botocore/boto3 vectors.

AWS Toolkit
Aug 25, 2026

v0.16.1 — MFA, social sign-in, multipart & streaming

The AWS toolkit's pre-release build now covers every major flow: SRP and password auth with MFA continuation (SMS/TOTP/e-mail), Hosted UI social sign-in via OAuth2 + PKCE with suspension-proof deep links, S3 storage including multipart uploads with gap protection, DynamoDB typed data with expression builders and transactions, Lambda invocation plus CRC-verified response streaming, offline mutation queues, feature flags, analytics, and an eight-tab editor suite ending in a one-button live smoke test.

Pre-release — full history lives in the package changelog.

Supabase Toolkit
Aug 26, 2026

v1.51.0 — the Live Ops composer

A Live Ops tab for running a season from the editor: broadcast mail with a dry-run recipient count and typed confirmation, cohort targeting filtered server-side, an announcements manager, a push composer and broadcasts scheduled through pg_cron.

  • RLS pentest runner: queries every public table as the anon key, optionally as a signed-in test player, and reports what leaks.
  • Economy and experiments dashboards: faucet-versus-sink breakdowns with an inflation warning, and A/B conversion with a two-proportion z-test.
  • Airplane mode: one toggle routes every request through an in-memory backend, for demos with no project, network or keys.
  • Seven finished tabs that were unreachable since v1.44 are back in the sidebar, and a CI SQL guard lints every pack on each pull request.
Apply the new Live Ops
pack to use the
composer.
Supabase Toolkit
Aug 24, 2026

v1.50.0 — the developer-experience release

Schema snapshot and diff in the Migrations tab: capture the live schema, diff it later, and get migration SQL stubs for everything mechanical while destructive changes stay commented for review.

  • Local development loop: start, stop and read the Supabase CLI stack from the Environments tab, and generate a local settings asset in one click.
  • Auto-refresh now runs on the Unity main thread, and the Setup Check advisor fails hard when a game client can reach the dev-only SQL executor.
  • A release-readiness gate runs in CI, the Setup Wizard flags a dashboard URL pasted where the API URL belongs, and llms.txt is published for AI agents.
Supabase Toolkit
Aug 23, 2026

v1.49.0 — search, scheduled jobs and a security advisor

Two new backend packs: Hybrid Search fuses keyword and vector rankings server-side with Reciprocal Rank Fusion, and Scheduled Jobs wraps Supabase Cron with service-role-only scheduling and run history.

  • Security advisor: live checks for tables without RLS, SECURITY DEFINER functions without a pinned search path, exposed definer functions, public storage buckets and always-true policies.
  • A Queues view and a Cron tab join the web Live-Ops dashboard, and failed storage calls now explain their real cause.
  • A PlayMode smoke suite pins the runtime glue EditMode cannot reach.
Supabase Toolkit
Aug 23, 2026

v1.48.0 — streaming, pagination and queues

Edge Function streaming: InvokeStreamingAsync delivers response chunks as they arrive, raw or parsed as Server-Sent Events, on the Unity main thread. This is the missing piece for proxying AI providers through your own Edge Functions.

  • GetAllAsync(pageSize, maxRows) walks pages until a short page arrives, with a hard row cap.
  • Queues pack on Supabase Queues (pgmq), with a registry that decides which queues signed-in clients may use.
Supabase Toolkit
Aug 23, 2026

v1.47.0 — playable sample and a getting-started checklist

The Complete Game sample now ships a ready-made scene that builds its own UI at Play time, and the Dashboard tracks four live checks between import and a working backend, each with a one-click fix.

  • The web Live-Ops dashboard gains an Analytics tab with daily volume, top events and CSV export.
  • Diagnostics rebuilt with per-service reachability probes and a copyable report; samples import in one click.
  • Verify Release Readiness checks package metadata, sample scenes and docs before store submission, and CI runs the EditMode suite on every push.
Supabase Toolkit
Aug 22, 2026

v1.46.3 — SRP-safe bundled text shader

The TextMeshPro distance-field shader shipped inside the package now declares separate SubShaders with single-value render-pipeline tags (URP, HDRP) plus an untagged Built-in fallback. v1.46.2 and v1.46.3 are two rounds of the same fix.

Text renders identically in every pipeline and passes modern Asset Store validation without any manual shader setup.

No action needed.
Re-import the package and
existing UI keeps working.
Supabase Toolkit
Aug 21, 2026

v1.46.1 — cleaner sample scenes

Demo scenes no longer embed uGUI or Input System component GUIDs. The demo runner builds its Canvas, UI panel and EventSystem at runtime from a serialized prefab reference.

  • Samples import with zero missing components in any project.
  • Works whether or not the Input System package is installed.
No action needed.
Scenes regenerate via
Tools > ShipIt > Samples.
Supabase Toolkit
Aug 21, 2026

v1.46.1 — Fast Enter Play Mode and validation hardening

All toolkit static state resets between Play sessions when domain reload is disabled, and the Poppins SDF font material now uses a shader that ships inside the package.

  • Fast Enter Play Mode: client singleton, request and realtime inspectors, logger buffers and test transports reset via RuntimeInitializeOnLoadMethod(SubsystemRegistration).
  • Static events: inspector and logger subscribers are unregistered automatically on Play-mode state change.
  • No TMP Essentials dependency: text works out of the box in fresh projects.
Editor caches invalidate
automatically on play mode
state change.
Supabase Toolkit
Aug 21, 2026

v1.46.0 — analytics pack, the 34th backend pack

A batched analytics_events table for DAU, funnels and retention, secured so clients can only insert their own events while dashboards read with the service role.

  • Pairs with AnalyticsService.Track() and auto-flush (25 events or ~20 s).
  • Indexes included: event + time, user + time.
  • Every feature service in the toolkit now maps to a SQL pack.
Provision tab → tick
Analytics Events → apply.
Supabase Toolkit
Aug 20, 2026

v1.45.0 — production reliability

The failure modes that appear after prototypes become real games, handled deliberately:

  • AOT-safe typed queries — lambda filters no longer use Expression.Compile(), keeping IL2CPP safe.
  • Resilient auth refresh — transient failures retry with bounded backoff instead of dropping sessions.
  • Realtime auth lifecycle — sign-in/out and token refresh propagate to private channels automatically.
  • Complete OAuth PKCE — deep links, code exchange, legacy token import.
  • Truly resumable uploads — TUS locations survive restarts; ambiguous failures reconcile before retrying.
  • Test suite grew to 130 EditMode tests.
Full details in the
package CHANGELOG.md.
Supabase Toolkit
Jul 2026

v1.44.0 — SDK parity and security hardening

  • Auth — persisted-session expiry fixes, CAPTCHA-aware sign-ins, Apple/Google ID-token flows, identity linking.
  • Database — negated filters, OR expressions, culture-invariant dates, offline-cache correctness.
  • Realtime — per-filter channels, join acknowledgements, DELETE payloads delivered.
  • Storage — listing with prefix/search/pagination/sorting, path-traversal rejection.
  • Security — service-role keys moved to machine-local editor storage; economy, quest and battle-pass mutations became service-role-only RPCs.
The first version
submitted to the
Asset Store.
Upgrading

How to update an existing project

  • Asset Store buyers — download the new package from your Purchases page and re-import; nothing outside Assets/ShipIt/Supabase is touched.
  • UPM users — refresh in Package Manager or point the manifest at the new tarball.
  • SQL packs are idempotent — re-running them is safe and picks up policy and function improvements.
Questions?
shipit.unity@gmail.com