Workflow 2.2.18 keeps accepted external signal inputs bounded in durable command and history records. The command retains the immutable payload reference, and both workflow worker paths store large applied signal values through the configured external storage policy. Replay resolves the original bytes and preserves declared argument order, defaults and variadic arguments.
The change is covered by an external Avro signal regression, a cold-replay corpus fixture, bridge and contract tests, and the full MySQL, PostgreSQL, MariaDB, unit coverage, quality and supported Laravel upgrade matrix. Published-package verification passed, including Packagist source identity, the platform contract and supported Laravel upgrades. Packagist resolves this release to commit 09158ab3fb4cfa5e46e320e2d70853122af209cc.
Server pins its own Workflow package version. The Server ingress change and published-image conformance are tracked in Server #262. The implementation PR contains the source qualification evidence.