Skip to content

Releases: AjnasNB/maqam

Maqam v0.3.2 — release-truth patch

Choose a tag to compare

@AjnasNB AjnasNB released this 19 Jul 23:42
ea3266e

Release-truth patch for the immutable npm README.

  • Corrects the ProductLoop OS companion reference to 0.2.2.
  • Keeps Maqam runtime, policy, approval, browser, crawler, research, and credential boundaries unchanged.
  • Supports Node.js 22 LTS, 24 LTS, and 26 Current.
  • Published through npm Trusted Publishing with SLSA provenance.

Verified identity:

  • Commit: ea3266e
  • Tarball: maqam-0.3.2.tgz (348,328 bytes)
  • SHA-256: 30402c9d9badf45e691fd8d3199a9c4e60b97a32c27850a7449e0ba3bca18f53
  • npm integrity: sha512-KMLhPi1Yt58icbWbpvCn83uwUvK3VDC/H5nF40GJmPMHwGK69WvVpCZe3KgB+HcEMqfjXHoSgNec8/Lg1Ohr/g==
  • Exact-clean-main MGES: 14/14 conformance; 129.273 microseconds/call median; 2.0305% CV; publication criteria PASS.

The benchmark is local component regression evidence, not a security certification, competitor benchmark, or SLA.

Maqam 0.3.1 — governed public research and browser actions

Choose a tag to compare

@AjnasNB AjnasNB released this 19 Jul 18:20
2f7231d

Maqam 0.3.1 makes governed public research and browser operations first-class while preserving the exact-call governance boundary.

Highlights:

  • Policy-gated YouTube metadata, RSS, web-crawler, and optional Exa adapters.
  • Structural browser observe, preview, apply, and submit operations with exact input-bound approval for writes.
  • Node.js 22, 24, and 26 support; active Node 20 runtime dependencies removed.
  • Reproducible MGES evidence: 14/14 conformance fixtures and 30-sample governed-overhead results.
  • npm Trusted Publishing with SLSA provenance and registry signature verification.

Published artifact:

See docs/release-0.3.1.md for the full capability, evidence, and limitation record.

Maqam v0.3.0 — Governed Public Research

Choose a tag to compare

@AjnasNB AjnasNB released this 18 Jul 16:34
98c2d97

Maqam 0.3.0 adds governed public-source routing while preserving exact policy, approval, trace, and evidence boundaries.

Highlights:

  • hosted-anonymous Exa web search with exact origin, redirect, byte, result, timeout, and cancellation controls
  • explicitly configured yt-dlp adapter for public YouTube metadata, search results, and available captions without browser cookies or media download
  • immutable network-origin declarations enforced before dispatch
  • bounded source API and local research console
  • strengthened exact-commit npm release identity and trusted OIDC publication
  • clean-main MGES v1.1 evidence: 14/14 conformance; 140.816 microseconds/call median; 138.983-142.820 interval; 5.020% governed CV

Verification:

  • npm Trusted Publishing run 29652119000
  • gitHead 98c2d97
  • npm integrity sha512-0fV354AKT6JtVMYzWcMCfjUQpJHIjaNF+bGjxq8TzcuElNVQsx3Cp5Yc062RgNJ5zSDVgUJSn1hzn04hT3jWuQ==
  • registry tarball SHA-256 eb3e4a29f94fdeef9b3bcc494661e3e5ce48affb241dcda7f8a9adcf0704308b

No-developer-key routes are public-data, best-effort integrations; they are not unlimited, authenticated, offline, or a promise of access to every page or video.

Maqam v0.2.4 — Exact approval, adapter conformance, MGES v1

Choose a tag to compare

@AjnasNB AjnasNB released this 17 Jul 15:35

Maqam 0.2.4 release notes

Maqam 0.2.4 adds a reproducible project benchmark, a provider-neutral tool-adapter contract, ProductLoop composition guidance, and a fully rendered 60-second proof video.

Maqam exact-approval gate

What changed

  • Added MGES v1 with separate local in-process performance and deterministic governance-boundary conformance profiles, raw observations, source fingerprints, versioned schemas, uncertainty, and copy-safe claim rules.
  • Added defineToolAdapter(), registerToolAdapter(), and runToolAdapterConformance() for host-supplied function, SDK, HTTP, MCP-style, and custom integrations.
  • Preserved stricter governance declared by an adapter handler and now reject ambiguous leading/trailing whitespace in adapter or handler governance labels before registration.
  • Added a real ProductLoop OS composition example through createProductLoopOS().maqamGateway.
  • Added standard CLI version reporting through maqam --version and maqam -v, covered by the release test suite.
  • Added benchmark, integration, comparison, Why Maqam, roadmap, release, and technical-article documentation.
  • Added a 60-second Remotion demo with local TTS, portable SRT/VTT captions, benchmark proof, ecosystem limits, and seven launch stills.

MGES v1 result

The clean Windows x64 / Node 24.15.0 / Ryzen 7 4800H local-call profile recorded a governed median of 127.498 microseconds per call, a 126.334–128.942 microsecond 95% deterministic percentile-bootstrap interval for the sample median, 5.572% coefficient of variation, and 5/5 project publication checks passed across 30 fresh-process observations per variant. The separate governance-boundary profile passed 12/12 named fixtures.

MGES is Maqam's project-defined regression and conformance suite. It is not a globally standardized benchmark, certification, penetration test, security score, competitor ranking, production capacity result, or SLA.

Verified release

  • Final Git commit: e1f6d3f9cf0d4aac277fc5e6ba1de3ae2c93a701
  • Published package: maqam@0.2.4
  • Trusted publication: GitHub Actions run 29587323309 completed with npm OIDC provenance at the exact release commit
  • Clean measured source commit: 44c198f9eab1ea3a2dedb1f784413a2733b7745d
  • Local tests: 204/204 passed
  • CI: run 29587185621 passed on Node 20, 22, and 24, including tests, clean-consumer TypeScript compilation, website contracts, production audit, and package dry run
  • CodeQL: run 29587183934 passed for JavaScript/TypeScript at the final commit
  • Dependency audit: zero production vulnerabilities; 30 verified registry signatures and one verified attestation
  • Exact tarball: 191,585 bytes; 65 entries; 735,377 unpacked bytes; SHA-256 f4751f4f4ef3a4a97631f8ebddc72cb03962cc52d7ae983f9d0188de9a6318cb; npm integrity sha512-/VHGyLNele7rp7At6HGZhrw5UxOF9rlcPWHWZ+7srMz47zhhEBbkJXgKQTdZRA0MLQTGqGs8sKFhNnhgjIPWlA==; independent repack byte-identical
  • Exact-tarball consumer: Maqam 0.2.4 and ProductLoop OS 0.2.0 installed together, deduplicated to Maqam 0.2.4, loaded all nine namespaces, passed productloop-os doctor --json, completed a governed adapter call, and passed all seven adapter conformance checks
  • Videos: one 60-second exact-approval proof and two 55-second ProductLoop/crawler explainers, all 1920x1080 at 30 fps with narration, posters, SRT/VTT captions, and visual QA

Important boundaries

Maqam governs only calls routed through registered gateway tools. The host remains responsible for provider credentials, SDK/MCP clients, discovery, protocol validation, HTTP and operating-system isolation, secrets, durable storage, retries, rate limits, reviewer authentication, and deployment monitoring. Passing these tests is evidence for the covered behavior, not proof that Maqam or a deployment is defect-free.

Publication state

maqam@0.2.4 is public on npm. The registry reports Git commit e1f6d3f9cf0d4aac277fc5e6ba1de3ae2c93a701 and integrity sha512-/VHGyLNele7rp7At6HGZhrw5UxOF9rlcPWHWZ+7srMz47zhhEBbkJXgKQTdZRA0MLQTGqGs8sKFhNnhgjIPWlA==, matching this release manifest. The annotated v0.2.4 tag resolves to the same commit.

Maqam v0.2.3 — exact-approval proof and launch kit

Choose a tag to compare

@AjnasNB AjnasNB released this 16 Jul 13:31

Maqam 0.2.3 — exact-approval proof and launch kit

Maqam is a compact MIT-licensed TypeScript governance layer for agent and workflow tool calls: policy before execution, approval bound to the exact call, and source-linked evidence behind recorded claims.

What changed

  • Added maqam demo approval and maqam demo approval --json, a deterministic real temporary-file flow that blocks changed input before execution, executes the exact approved write once, rejects replay, links evidence to a claim, and verifies cleanup.
  • Added regression tests for the approval request, canonical input scope mismatch, one-use consumption, replay rejection, evidence linkage, and deterministic CLI output.
  • Added a reproducible local governed-call overhead microbenchmark with raw output and explicit interpretation limits.
  • Published a five-minute quickstart, Why Maqam guide, dated comparison, enforcement-boundary diagram, public roadmap, technical article, launch plan, and factual Show HN author brief.
  • Added the source, captions, narration, poster, and proof stills for the 60-second Remotion demonstration. The release MP4 is generated from the real CLI JSON.

Try it

npm install maqam@0.2.3
npx -y maqam@0.2.3 demo approval

Machine-readable proof:

npx -y maqam@0.2.3 demo approval --json

Verification

  • 189 Node tests passed locally.
  • Clean external TypeScript consumer compilation passed.
  • Production npm audit: 0 known vulnerabilities.
  • Remotion project audit: 0 known vulnerabilities.
  • Public-package dry run: 50 files; video source and launch drafts excluded from the npm tarball.
  • Release commit: 7a07d944e79283dd8c27131c41896d59fbe31249.
  • GitHub Actions passed on Node.js 20, 22, and 24 before tagging.
  • The release MP4 fully decoded as H.264/AAC, 1920×1080, 30 fps, exactly 60.000 seconds. Audio measured -19.2 LUFS integrated with a -3.5 dBFS true peak.

See SHA256SUMS.txt for artifact hashes.

Important boundary

Maqam governs only calls routed through registered adapters. Current approval, trace, runtime, and evidence state is in-process. ApprovalQueue does not authenticate reviewer identity, restored state must come from trusted host storage, evidence links record provenance rather than semantic truth, and Maqam is not an operating-system sandbox or durable workflow engine.

Documentation

Compatibility

Maqam requires Node.js >=20.18.1. ProductLoop OS 0.2.0 already declares maqam:^0.2.2, so it accepts this patch without republishing ProductLoop packages.

License note

Maqam remains MIT-licensed. The repository-only Remotion rendering toolchain has separate upstream terms documented in LICENSE_AUDIT.md and demo/remotion/ASSET_PROVENANCE.md.

Maqam v0.2.2

Choose a tag to compare

@AjnasNB AjnasNB released this 15 Jul 17:17

Security-focused runtime hardening release. Strengthens approval, evidence, provider, workflow, CLI, and server trust boundaries; adds exact-origin CORS controls and expanded adversarial coverage. Verified on Node.js 20, 22, and 24. npm: https://www.npmjs.com/package/maqam/v/0.2.2

Release-proof assets

Maqam 0.2.1

Choose a tag to compare

@AjnasNB AjnasNB released this 15 Jul 15:28

Security and packaging patch for exact approval-input binding, immutable tool metadata, fail-closed policy decisions, strict restored-approval validation, raw embedded-server listen guards, clean TypeScript consumption, and pinned Node 20/22/24 CI. See CHANGELOG.md and SECURITY.md for details. This release was independently reviewed and verified from a fresh npm registry install.

Maqam 0.2.0

Choose a tag to compare

@AjnasNB AjnasNB released this 15 Jul 14:32

Public npm release of the provider-neutral governed agent framework and bounded crawler. Adds deny-by-default policy, input-bound one-use approvals, provenance and evidence controls, provider adapters, and crawler protections for SSRF, redirects, robots, private networks, budgets, retries, and concurrency.

Maqam v0.1.6

Choose a tag to compare

@AjnasNB AjnasNB released this 30 Jun 11:15

Added\n- Universal Agent Control documentation with a workflow graph and adapter matrix.\n- Dashboard Agent control map showing function agents, object agents, CLI workers, connectors, approvals, and evidence.\n- End-to-end test proving one governed workflow can chain function, object, and CLI workers.\n\n## Changed\n- Public positioning now says Maqam is an MIT-licensed agent framework.\n- Console layout is more dashboard-focused, with run panel and metrics visible sooner.\n- CLI help text now says Maqam agent framework console.\n\n## Verification\n- npm test: 34 passing tests.\n- npm pack --dry-run verified package contents.\n- Clean npm install smoke verified universal worker control and maqam --help.

Maqam v0.1.4

Choose a tag to compare

@AjnasNB AjnasNB released this 30 Jun 11:00

Added\n- Governed CLI worker adapter via createCliAgentTool.\n- Timeout, approximate input-token, output-byte, JSON parsing, nonzero-exit, and spawn-failure controls for command-line workers.\n- End-to-end workflow test showing a governed worker producing a small artifact with evidence capture.\n- New visual flow asset for governed CLI worker orchestration.\n\n## Verification\n- npm test: 33 passing tests.\n- npm pack --dry-run verified package contents.\n- Clean npm install smoke verified maqam@0.1.4 exports and CLI help.