v1.3.0
Native GLM ACP v1.3.0
This release hardens execution, worker promotion, plugin trust, evaluation, and observability while preserving the native five-platform installation experience.
Highlights
- Stronger OS-aware command containment with Linux Bubblewrap, macOS Seatbelt, and fail-closed capability reporting.
- Verification- and digest-gated worktree worker promotion with conflict-aware transactional rollback.
- Language-aware bounded
@file,@folder,@symbol, and@diffcontext budgeting, including a runtime-free symbol-search fallback. - Redacted failure-driven evaluation corpus and an observability dashboard for quality, latency, token, cache, sandbox, plugin, and resilience signals.
- Ed25519 plugin signing, trusted-publisher enforcement, hash-pinned packages, and permission-scoped data-only plugins.
- Bounded fuzzing, fault injection, and lifecycle failure checks.
Distribution
Five checksum-verified frozen binaries are published for Linux x86-64/ARM64, macOS Intel/Apple Silicon, and Windows x86-64. Installers remain user-local, require no Python or Node.js runtime, and expose both native-glm-acp and glm-acp.
Full changelog: v1.2.0...v1.3.0