Releases: AjnasNB/maqam
Release list
Maqam v0.3.2 — release-truth patch
Release-truth patch for the immutable npm README.
- Corrects the ProductLoop OS companion reference to 0.2.2.
- Keeps Maqam runtime, policy, approval, browser, crawler, research, and credential boundaries unchanged.
- Supports Node.js 22 LTS, 24 LTS, and 26 Current.
- Published through npm Trusted Publishing with SLSA provenance.
Verified identity:
- Commit: ea3266e
- Tarball: maqam-0.3.2.tgz (348,328 bytes)
- SHA-256: 30402c9d9badf45e691fd8d3199a9c4e60b97a32c27850a7449e0ba3bca18f53
- npm integrity: sha512-KMLhPi1Yt58icbWbpvCn83uwUvK3VDC/H5nF40GJmPMHwGK69WvVpCZe3KgB+HcEMqfjXHoSgNec8/Lg1Ohr/g==
- Exact-clean-main MGES: 14/14 conformance; 129.273 microseconds/call median; 2.0305% CV; publication criteria PASS.
The benchmark is local component regression evidence, not a security certification, competitor benchmark, or SLA.
Maqam 0.3.1 — governed public research and browser actions
Maqam 0.3.1 makes governed public research and browser operations first-class while preserving the exact-call governance boundary.
Highlights:
- Policy-gated YouTube metadata, RSS, web-crawler, and optional Exa adapters.
- Structural browser observe, preview, apply, and submit operations with exact input-bound approval for writes.
- Node.js 22, 24, and 26 support; active Node 20 runtime dependencies removed.
- Reproducible MGES evidence: 14/14 conformance fixtures and 30-sample governed-overhead results.
- npm Trusted Publishing with SLSA provenance and registry signature verification.
Published artifact:
- npm: https://www.npmjs.com/package/maqam/v/0.3.1
- gitHead: 2f7231d
- SHA-256: 5c6357eefd431b1de1c03d8106e2cc63e2ddfe6d87511767dc47e991916d5e02
- Integrity: sha512-ZszRNaHqxoWls8bJ76ouptPwwNnbctfaolXP5PD3/pbFxj3fecvcuYmxSrnkvf2UxBUmWmzJls3hAuBAGqVIiA==
See docs/release-0.3.1.md for the full capability, evidence, and limitation record.
Maqam v0.3.0 — Governed Public Research
Maqam 0.3.0 adds governed public-source routing while preserving exact policy, approval, trace, and evidence boundaries.
Highlights:
- hosted-anonymous Exa web search with exact origin, redirect, byte, result, timeout, and cancellation controls
- explicitly configured yt-dlp adapter for public YouTube metadata, search results, and available captions without browser cookies or media download
- immutable network-origin declarations enforced before dispatch
- bounded source API and local research console
- strengthened exact-commit npm release identity and trusted OIDC publication
- clean-main MGES v1.1 evidence: 14/14 conformance; 140.816 microseconds/call median; 138.983-142.820 interval; 5.020% governed CV
Verification:
- npm Trusted Publishing run 29652119000
- gitHead 98c2d97
- npm integrity sha512-0fV354AKT6JtVMYzWcMCfjUQpJHIjaNF+bGjxq8TzcuElNVQsx3Cp5Yc062RgNJ5zSDVgUJSn1hzn04hT3jWuQ==
- registry tarball SHA-256 eb3e4a29f94fdeef9b3bcc494661e3e5ce48affb241dcda7f8a9adcf0704308b
No-developer-key routes are public-data, best-effort integrations; they are not unlimited, authenticated, offline, or a promise of access to every page or video.
Maqam v0.2.4 — Exact approval, adapter conformance, MGES v1
Maqam 0.2.4 release notes
Maqam 0.2.4 adds a reproducible project benchmark, a provider-neutral tool-adapter contract, ProductLoop composition guidance, and a fully rendered 60-second proof video.
What changed
- Added MGES v1 with separate local in-process performance and deterministic governance-boundary conformance profiles, raw observations, source fingerprints, versioned schemas, uncertainty, and copy-safe claim rules.
- Added
defineToolAdapter(),registerToolAdapter(), andrunToolAdapterConformance()for host-supplied function, SDK, HTTP, MCP-style, and custom integrations. - Preserved stricter governance declared by an adapter handler and now reject ambiguous leading/trailing whitespace in adapter or handler governance labels before registration.
- Added a real ProductLoop OS composition example through
createProductLoopOS().maqamGateway. - Added standard CLI version reporting through
maqam --versionandmaqam -v, covered by the release test suite. - Added benchmark, integration, comparison, Why Maqam, roadmap, release, and technical-article documentation.
- Added a 60-second Remotion demo with local TTS, portable SRT/VTT captions, benchmark proof, ecosystem limits, and seven launch stills.
MGES v1 result
The clean Windows x64 / Node 24.15.0 / Ryzen 7 4800H local-call profile recorded a governed median of 127.498 microseconds per call, a 126.334–128.942 microsecond 95% deterministic percentile-bootstrap interval for the sample median, 5.572% coefficient of variation, and 5/5 project publication checks passed across 30 fresh-process observations per variant. The separate governance-boundary profile passed 12/12 named fixtures.
MGES is Maqam's project-defined regression and conformance suite. It is not a globally standardized benchmark, certification, penetration test, security score, competitor ranking, production capacity result, or SLA.
Verified release
- Final Git commit:
e1f6d3f9cf0d4aac277fc5e6ba1de3ae2c93a701 - Published package:
maqam@0.2.4 - Trusted publication: GitHub Actions run 29587323309 completed with npm OIDC provenance at the exact release commit
- Clean measured source commit:
44c198f9eab1ea3a2dedb1f784413a2733b7745d - Local tests: 204/204 passed
- CI: run 29587185621 passed on Node 20, 22, and 24, including tests, clean-consumer TypeScript compilation, website contracts, production audit, and package dry run
- CodeQL: run 29587183934 passed for JavaScript/TypeScript at the final commit
- Dependency audit: zero production vulnerabilities; 30 verified registry signatures and one verified attestation
- Exact tarball: 191,585 bytes; 65 entries; 735,377 unpacked bytes; SHA-256
f4751f4f4ef3a4a97631f8ebddc72cb03962cc52d7ae983f9d0188de9a6318cb; npm integritysha512-/VHGyLNele7rp7At6HGZhrw5UxOF9rlcPWHWZ+7srMz47zhhEBbkJXgKQTdZRA0MLQTGqGs8sKFhNnhgjIPWlA==; independent repack byte-identical - Exact-tarball consumer: Maqam 0.2.4 and ProductLoop OS 0.2.0 installed together, deduplicated to Maqam 0.2.4, loaded all nine namespaces, passed
productloop-os doctor --json, completed a governed adapter call, and passed all seven adapter conformance checks - Videos: one 60-second exact-approval proof and two 55-second ProductLoop/crawler explainers, all 1920x1080 at 30 fps with narration, posters, SRT/VTT captions, and visual QA
Important boundaries
Maqam governs only calls routed through registered gateway tools. The host remains responsible for provider credentials, SDK/MCP clients, discovery, protocol validation, HTTP and operating-system isolation, secrets, durable storage, retries, rate limits, reviewer authentication, and deployment monitoring. Passing these tests is evidence for the covered behavior, not proof that Maqam or a deployment is defect-free.
Publication state
maqam@0.2.4 is public on npm. The registry reports Git commit e1f6d3f9cf0d4aac277fc5e6ba1de3ae2c93a701 and integrity sha512-/VHGyLNele7rp7At6HGZhrw5UxOF9rlcPWHWZ+7srMz47zhhEBbkJXgKQTdZRA0MLQTGqGs8sKFhNnhgjIPWlA==, matching this release manifest. The annotated v0.2.4 tag resolves to the same commit.
Maqam v0.2.3 — exact-approval proof and launch kit
Maqam 0.2.3 — exact-approval proof and launch kit
Maqam is a compact MIT-licensed TypeScript governance layer for agent and workflow tool calls: policy before execution, approval bound to the exact call, and source-linked evidence behind recorded claims.
What changed
- Added
maqam demo approvalandmaqam demo approval --json, a deterministic real temporary-file flow that blocks changed input before execution, executes the exact approved write once, rejects replay, links evidence to a claim, and verifies cleanup. - Added regression tests for the approval request, canonical input scope mismatch, one-use consumption, replay rejection, evidence linkage, and deterministic CLI output.
- Added a reproducible local governed-call overhead microbenchmark with raw output and explicit interpretation limits.
- Published a five-minute quickstart, Why Maqam guide, dated comparison, enforcement-boundary diagram, public roadmap, technical article, launch plan, and factual Show HN author brief.
- Added the source, captions, narration, poster, and proof stills for the 60-second Remotion demonstration. The release MP4 is generated from the real CLI JSON.
Try it
npm install maqam@0.2.3
npx -y maqam@0.2.3 demo approvalMachine-readable proof:
npx -y maqam@0.2.3 demo approval --jsonVerification
- 189 Node tests passed locally.
- Clean external TypeScript consumer compilation passed.
- Production npm audit: 0 known vulnerabilities.
- Remotion project audit: 0 known vulnerabilities.
- Public-package dry run: 50 files; video source and launch drafts excluded from the npm tarball.
- Release commit:
7a07d944e79283dd8c27131c41896d59fbe31249. - GitHub Actions passed on Node.js 20, 22, and 24 before tagging.
- The release MP4 fully decoded as H.264/AAC, 1920×1080, 30 fps, exactly 60.000 seconds. Audio measured -19.2 LUFS integrated with a -3.5 dBFS true peak.
See SHA256SUMS.txt for artifact hashes.
Important boundary
Maqam governs only calls routed through registered adapters. Current approval, trace, runtime, and evidence state is in-process. ApprovalQueue does not authenticate reviewer identity, restored state must come from trusted host storage, evidence links record provenance rather than semantic truth, and Maqam is not an operating-system sandbox or durable workflow engine.
Documentation
- Five-minute quickstart
- Why Maqam
- Detailed comparison
- Public roadmap
- Technical article
- Security policy
- npm package
Compatibility
Maqam requires Node.js >=20.18.1. ProductLoop OS 0.2.0 already declares maqam:^0.2.2, so it accepts this patch without republishing ProductLoop packages.
License note
Maqam remains MIT-licensed. The repository-only Remotion rendering toolchain has separate upstream terms documented in LICENSE_AUDIT.md and demo/remotion/ASSET_PROVENANCE.md.
Maqam v0.2.2
Security-focused runtime hardening release. Strengthens approval, evidence, provider, workflow, CLI, and server trust boundaries; adds exact-origin CORS controls and expanded adversarial coverage. Verified on Node.js 20, 22, and 24. npm: https://www.npmjs.com/package/maqam/v/0.2.2
Release-proof assets
Maqam 0.2.1
Security and packaging patch for exact approval-input binding, immutable tool metadata, fail-closed policy decisions, strict restored-approval validation, raw embedded-server listen guards, clean TypeScript consumption, and pinned Node 20/22/24 CI. See CHANGELOG.md and SECURITY.md for details. This release was independently reviewed and verified from a fresh npm registry install.
Maqam 0.2.0
Public npm release of the provider-neutral governed agent framework and bounded crawler. Adds deny-by-default policy, input-bound one-use approvals, provenance and evidence controls, provider adapters, and crawler protections for SSRF, redirects, robots, private networks, budgets, retries, and concurrency.
