Repeated adoption reviews exposed where a small portable abstraction still forced mature products to retain too much provider-specific plumbing. This batch expands those contracts while leaving deployment and product policy with the application.
Richer storage and queue control
Storage now supports bounded listing and prefix deletion, copy, byte ranges, conditional writes, integrity verification, abort signals, and an optional multipart surface. S3-compatible, R2, filesystem, and memory providers report their exact capabilities. @playstack/nest-storage adds stable named-store injection.
Queues now carry structured progress and expose an optional control plane for progress subscriptions, schedules, bounded inspection, counts, and cancellation. @playstack/nest-queues provides named injection, typed handler discovery, and worker lifecycle composition. BullMQ 5.16 through 6.x is an explicit supported range.
Safer migrations
Rate limiting adds an explicit fixed-window strategy for products that cannot change throttling semantics during adoption. API keys add atomic grace-period rotation, family revocation, and legacy verification seams. Crypto adds application-owned legacy envelope readers that return current replacement ciphertext for compare-and-swap migration.
Push and outbound delivery
Notifications can route push jobs through registered encrypted device targets. Delivery provides APNs, Expo, FCM, and Web Push provider boundaries with permanent-token feedback.
Webhooks now complements verified inbound receipt with direct, self-hosted durable, and Relaypath-backed outbound dispatch. Applications can route accepted audience or domain events to Slack, Discord, or product endpoints without making those providers part of the originating package.