Skip to content

Releases: DACS-Agent-commerce/dacs-sdk

DACS one-click Docker acceptance preview — PR #312 b61def4b r2

Choose a tag to compare

DACS one-click Docker acceptance preview — PR #312

This r2 wrapper supersedes r1. The exact source commit and package archives
are unchanged; r2 also omits optional dependencies during its two host-side
bootstrap installs. The generated Docker build already omitted them.

This is an immutable, unapproved engineering preview built from PR #312 commit
b61def4b2a5efcc0ed886636e2b5dd2ad3d48e0b (tree
12b71ea6a0327183577665053585084e217df2f4). It is not the protected npm
prerelease, not maintainer-approved, and not production-ready.

It contains the complete PR #303 one-click integration plus one focused Docker
acceptance repair:

  • install and image assembly omit npm's audit/funding network requests;
  • the dedicated release audit and SBOM gates remain unchanged;
  • the generated project exposes npm run dacs:image:smoke -- <image>;
  • the preview installer automatically runs that command after building;
  • the command inspects the non-root image configuration and executes an
    ephemeral container with no network and a read-only root filesystem;
  • it verifies UID/GID 10001, the exact service command, required compiled files,
    absence of source/test/secret inputs, exact package versions, and the Demos
    subpaths actually used by the SDK adapter.

Local clean-layer validation at this exact head produced:

  • Docker build: 54.44 seconds;
  • production install layer: 22.4 seconds;
  • npm prune: 2.0 seconds, down from about seven minutes in the independent VPS
    smoke;
  • runtime image smoke: 6.51 seconds, pass;
  • image sha256:57d3b057274ceec10ec9af02acb81a700bcf5895875394c1430307a1018a1228;
  • Node 20.19.1, UID/GID 10001, exact package versions, no credentials and no
    network access.

The exact three-package release set was built twice reproducibly and verified at
version 0.1.0-alpha.0, DACS Standard revision
662be1d4899a2cadf327fe2d5523e93a80334e5f, and SQLite schema v8. The core and
host tarballs are byte-identical to the prior exact integration preview; the
generator tarball is new for PR #312.

Known boundaries remain:

  • PR #312 is draft and stacked on draft PR #303; neither is approved or
    merge-ready.
  • Demos root ESM importability remains upstream PR kynesyslabs/sdks#121.
  • The Demos production graph still resolves Node-22.22-only packages under an
    advertised Node 20 runtime and carries unused multichain/deprecated packages;
    this is tracked by SDK #191. The narrow package implementation has merged
    upstream, but @kynesyslabs/demos-native@0.1.0-alpha.0 is not yet published;
    upstream issue kynesyslabs/sdks#123 remains open for that release. No
    downstream override is applied.
  • Fresh pre-start doctor is expected to exit 5 without credentials. The
    installer performs no setup, payment, fulfilment, service start or chain write.
  • Post-start doctor, restart/replay validation, and separately capped funded
    x402/pay-DEM tests remain guarded live acceptance steps.
  • Demos mainnet trust bootstrap remains blocked by SDK #284 and upstream
    kynesyslabs/node#994; use the configured development endpoint for guarded
    testnet work only.

DACS one-click Docker acceptance preview — PR #312 b61def4b r1 (superseded)

Choose a tag to compare

Superseded by r2: https://github.com/DACS-Agent-commerce/dacs-sdk/releases/tag/dacs-agent-preview-pr312-b61def4b-r2

The exact source commit and package archives are unchanged. The r2 wrapper also omits optional dependencies during both host-side bootstrap installs. Do not use r1 for new validation.

DACS one-click safety preview r2 — PR #303 faa5bd76

Choose a tag to compare

DACS one-click safety preview r2 — PR #303 exact head

This is an immutable, unapproved engineering preview built from PR #303 commit
faa5bd76e83720273bc83d3b888f202b2c29114a (tree
14c08995a6f858574e5c6ae67d0517fa5a721599). It is not the protected npm
prerelease, not maintainer-approved and not production-ready.

The installer accepts one explicit payment capability:

  • x402: Base/EVM x402 only;
  • pay-dem: native DEM only, with EVM/x402 dependencies omitted;
  • both: two separate signed rail offers, with each order selecting exactly one
    rail and no fallback after selection.

It downloads the exact core, Node host and generator tarballs from this GitHub
prerelease, checks their pinned SHA-256 digests, generates an
authority-separated buyer-and-seller deployment (with the selected role used
only as the default for direct local commands), replaces the unpublished package versions with immutable
release-asset URLs, installs with lifecycle scripts disabled, rebuilds only
better-sqlite3, and runs typecheck, generated tests and the read-only pre-start
doctor. It defaults to https://dev.node2.demos.sh for guarded testnet work.

Revision 2 verifies the installed package versions and exact lockfile-resolved
asset URLs, then restores the generated manifest's normative semver bindings.
This keeps the unpublished preview reproducible while allowing doctor and the
generated Docker npm ci step to enforce the same version contract as a future
registry release.

This candidate integrates the current adversarial safety stack: generation-fenced
settlement recovery, SSRF-resistant x402 transport, wallet-wide spend authority,
durable filesystem admission, bounded authenticated HTTP retention, narrowed
wallet capabilities, authenticated EVM finality/evidence, and strict dependency
advisory checks. It also includes the integration repairs found only through
packed-consumer testing: complete evidence-verification context, safe renewed
HTTP replay semantics, retained envelope identity, schema-v8 reconciliation, and
upgrade/restore handling for stores already at the target schema. This head also
serializes every authoritative x402 buyer, seller receipt, Demos wallet-journal,
and coordinator session lock mutation so stale recovery cannot delete a valid
successor owner.

Exact-head validation with Node 20.19.6:

  • the exact integration typecheck and 123 focused session/coordinator tests passed;
  • the complete integrated core suite passed deterministically on one worker:
    133 files and 3,458 tests, with only the repository's expected skips, todos
    and expected-fail vectors;
  • the session-lock component's full core suite passed: 127 files and 3,293 tests,
    with only the repository's expected skips, todos and expected-fail vectors;
  • host typecheck and all 528 host tests passed; generator typecheck and all 14
    generator tests passed;
  • all three packages built, package lifecycle verification passed, and the core
    package content/reproducibility check passed;
  • the exact three-package release set verified at 0.1.0-alpha.0, DACS Standard
    662be1d4899a2cadf327fe2d5523e93a80334e5f, SQLite schema v8, with SBOMs;
  • clean packed buyer+x402, buyer+pay-DEM and seller+both projects generated,
    installed, typechecked and passed their generated bootstrap/recovery tests;
  • all six exact-head GitHub checks passed, including Node 20/22, both clean
    packed live consumers, reproducibility/Bun, and secret scanning.
  • the published r2 installer was then executed from its public GitHub URL in
    a new directory: checksums, install, lock consistency, SQLite rebuild,
    typecheck, all 10 generated tests, and the expected read-only doctor exit 5
    passed; its default Docker build also completed and produced image
    sha256:33e55d9e38f21d47f6fff78611287956f1e5706bb310a8ccbc6b5bfa06ffc15a.
    The runtime image uses UID/GID 10001, contains the exact core/host versions
    and compiled output, excludes source, tests and .env, and fails closed
    when launched without its role configuration. No setup, payment, fulfilment,
    service start, or chain write occurred.

Known preview boundaries:

  • #303 is an integration proof, not a substitute for component review; it must
    remain draft until its dependency PRs are reviewed and merged in order.
  • No funded transaction was sent from this exact head. Use only separately capped,
    explicitly guarded testnet funding for live validation.
  • Demos mainnet trust bootstrap remains blocked by SDK #284 and upstream
    kynesyslabs/node#994; do not use this preview for mainnet funded effects.
  • The generated project contains deployment/runtime scaffolding, but operators
    must supply their own separate identities, secrets, balances and fulfilment
    callback and must pass both pre-start and post-start doctor gates.
  • A standalone live verifier service is not implemented in this candidate. The
    generated live deployment runs separate buyer and seller services; the
    installer role option selects only the default role for direct local
    commands. The offline profile retains its clearly labelled logical verifier
    simulation.
  • The installer fails unless Docker and its daemon are available, except when
    the operator explicitly selects --skip-docker-build. The exact public-path
    image build passed locally; configuring secrets, starting both role services,
    and funded testnet validation remain separate guarded VPS acceptance steps.

This preview is suitable for clean-VPS installation, configuration, Docker,
recovery and guarded testnet assessment. It is deliberately unsuitable for an
unreviewed production deployment.

WITHDRAWN — DACS preview PR #303 faa5bd76 r1

Choose a tag to compare

WITHDRAWN — do not install this preview

The first public installer revision is withdrawn. Clean public-path validation
found that it left immutable release-asset URLs in the generated
package.json, so the read-only doctor correctly failed the SDK version-binding
check with exit 1 instead of reaching the expected safely blocked exit 5.

No setup, payment, fulfilment, or chain write occurred. The package artifacts
remain the exact PR #303 faa5bd76 build, but this installer must not be used.
A separately tagged corrected preview will replace it after clean public-path
validation.

DACS multirail one-click preview (PR #196 @ ff885ac5)

Choose a tag to compare

DACS multirail one-click preview — PR #196 exact head

This is an immutable, unapproved engineering preview built from PR #196 commit
ff885ac524bbf5d62028ef9191463d9b2f137324. It is not the protected npm
prerelease, not maintainer-approved and not production-ready.

The installer now asks for one explicit payment capability:

  • x402: Base/EVM x402 only;
  • pay-dem: native DEM only, with EVM/x402 dependencies and secrets omitted;
  • both: two separate signed rail offers, with each purchase selecting one
    exact rail.

It downloads three exact package tarballs from this GitHub prerelease, verifies
their SHA-256 checksums, generates a buyer, seller or verifier project, pins the
unpublished DACS packages to immutable release assets, installs with lifecycle
scripts disabled, rebuilds only better-sqlite3, and runs typecheck, tests and
the read-only pre-start doctor. Generation does not create or fund wallets and
does not authorize setup, purchase, payment, fulfilment or a chain write.

Validation on the exact source head:

  • root typecheck/build and the full root suite passed: 115 files passed,
    7 skipped; 2,995 tests passed, 2 expected failures, 10 skipped, 159 todo;
  • Node host typecheck/build and full suite passed: 68 files passed, 2 skipped;
    418 tests passed, 2 skipped;
  • generator build and 12/12 tests passed;
  • six clean packed consumers passed: buyer and seller for x402, pay-dem and
    both; DEM-only consumers contained no x402, viem or EVM dependency;
  • a real SIGKILL after the native transfer hash/nonce checkpoint recovered
    from the same SQLite database, reconciled the retained transaction and did
    not call settlement again.

Known preview boundaries:

  • PR #196 is stacked on draft PR #190; both require Hayk's review before merge.
  • #191 blocks a production publication claim: the Demos SDK dependency tree
    contributes 66 clean-consumer production advisories (34 high, 3 critical).
  • #192 blocks the funded x402 proof until the provider-neutral Standard
    #274/#315 rail replaces the seller-specific legacy global endpoint.
  • #197 blocks the funded native proof: Demos SDK 4.0.16 and the current dev node
    disagree on post-fork GCR canonicalization. The guarded 1-OS attempt stopped
    before journalling or broadcast and balances were unchanged.
  • This preview is suitable for clean-VPS package, generation, configuration,
    doctor, Docker and recovery review. Do not use it for funded commerce until
    the applicable rail gate is repaired and a refreshed exact head is tested.

DACS multirail one-click preview (PR #196 @ eaf44a70)

Choose a tag to compare

DACS multirail one-click preview — PR #196 exact head

This is an immutable, unapproved engineering preview built from PR #196 commit
eaf44a705386b969f32537b799b87c22e75578b6. It is not the protected npm
prerelease, not maintainer-approved and not production-ready.

The installer now asks for one explicit payment capability:

  • x402: Base/EVM x402 only;
  • pay-dem: native DEM only, with EVM/x402 dependencies and secrets omitted;
  • both: two separate signed rail offers, with each purchase selecting one
    exact rail.

It downloads three exact package tarballs from this GitHub prerelease, verifies
their SHA-256 checksums, generates a buyer, seller or verifier project, pins the
unpublished DACS packages to immutable release assets, installs with lifecycle
scripts disabled, rebuilds only better-sqlite3, and runs typecheck, tests and
the read-only pre-start doctor. Generation does not create or fund wallets and
does not authorize setup, purchase, payment, fulfilment or a chain write.

Validation on the exact source head:

  • root typecheck/build and the full root suite passed: 115 files passed,
    7 skipped; 2,998 tests passed, 2 expected failures, 10 skipped, 159 todo;
  • Node host typecheck/build and full suite passed: 68 files passed, 2 skipped;
    418 tests passed, 2 skipped;
  • generator build and 12/12 tests passed;
  • six clean packed consumers passed: buyer and seller for x402, pay-dem and
    both; DEM-only consumers contained no x402, viem or EVM dependency;
  • a real SIGKILL after the native transfer hash/nonce checkpoint recovered
    from the same SQLite database, reconciled the retained transaction and did
    not call settlement again.
  • public EVM finality, direct ERC-20 and x402 settlement capture their exact
    negotiated inputs before any callback; adversarial mutation from chain,
    transfer and preflight callbacks cannot weaken amount or confirmation depth.

Known preview boundaries:

  • PR #196 is stacked on draft PR #190; both require Hayk's review before merge.
  • #191 blocks a production publication claim: the Demos SDK dependency tree
    contributes 66 clean-consumer production advisories (34 high, 3 critical).
  • #192 blocks the funded x402 proof until the provider-neutral Standard
    #274/#315 rail replaces the seller-specific legacy global endpoint.
  • #197 blocks the funded native proof: Demos SDK 4.0.16 and the current dev node
    disagree on post-fork GCR canonicalization. The guarded 1-OS attempt stopped
    before journalling or broadcast and balances were unchanged.
  • This preview is suitable for clean-VPS package, generation, configuration,
    doctor, Docker and recovery review. Do not use it for funded commerce until
    the applicable rail gate is repaired and a refreshed exact head is tested.

DACS multirail one-click preview (PR #196 @ 55c5731)

Choose a tag to compare

DACS multirail one-click preview — PR #196 exact head

This is an immutable, unapproved engineering preview built from PR #196 commit
55c57319a65d1a3195b98f8c90184211e929f9be. It is not the protected npm
prerelease, not maintainer-approved and not production-ready.

The installer now asks for one explicit payment capability:

  • x402: Base/EVM x402 only;
  • pay-dem: native DEM only, with EVM/x402 dependencies and secrets omitted;
  • both: two separate signed rail offers, with each purchase selecting one
    exact rail.

It downloads three exact package tarballs from this GitHub prerelease, verifies
their SHA-256 checksums, generates a buyer, seller or verifier project, pins the
unpublished DACS packages to immutable release assets, installs with lifecycle
scripts disabled, rebuilds only better-sqlite3, and runs typecheck, tests and
the read-only pre-start doctor. Generation does not create or fund wallets and
does not authorize setup, purchase, payment, fulfilment or a chain write.

Validation on the exact source head:

  • root typecheck/build and the full root suite passed: 115 files passed,
    7 skipped; 2,998 tests passed, 2 expected failures, 10 skipped, 159 todo;
  • Node host typecheck/build and full suite passed: 68 files passed, 2 skipped;
    418 tests passed, 2 skipped;
  • generator build and 12/12 tests passed;
  • six clean packed consumers passed: buyer and seller for x402, pay-dem and
    both; DEM-only consumers contained no x402, viem or EVM dependency;
  • a real SIGKILL after the native transfer hash/nonce checkpoint recovered
    from the same SQLite database, reconciled the retained transaction and did
    not call settlement again; the crash fixture retains a real event-loop handle
    until that kill and passed repeatedly on Node 20.19 as well as Node 22;
  • public EVM finality, direct ERC-20 and x402 settlement capture their exact
    negotiated inputs before any callback; adversarial mutation from chain,
    transfer and preflight callbacks cannot weaken amount or confirmation depth.

Known preview boundaries:

  • PR #196 is stacked on draft PR #190; both require Hayk's review before merge.
  • #191 blocks a production publication claim: the Demos SDK dependency tree
    contributes 66 clean-consumer production advisories (34 high, 3 critical).
  • #192 blocks the funded x402 proof until the provider-neutral Standard
    #274/#315 rail replaces the seller-specific legacy global endpoint.
  • #197 blocks the funded native proof: Demos SDK 4.0.16 and the current dev node
    disagree on post-fork GCR canonicalization. The guarded 1-OS attempt stopped
    before journalling or broadcast and balances were unchanged.
  • This preview is suitable for clean-VPS package, generation, configuration,
    doctor, Docker and recovery review. Do not use it for funded commerce until
    the applicable rail gate is repaired and a refreshed exact head is tested.

DACS one-click agent preview (PR #190 @ 7858352d)

Choose a tag to compare

DACS one-click agent preview — PR #190 exact head

This is an immutable, unapproved engineering preview built from PR #190 commit
7858352d638de206f6daaf77637088a90b8d2bed. It is not the protected npm
prerelease, not maintainer-approved, and not production-ready.

The preview exists so a clean VPS can validate the generated fixed-price x402
buyer/seller runtime before the dependency PRs receive Hayk's review. The
installer verifies all package checksums, generates from package artifacts,
pins its two unpublished DACS dependencies to immutable HTTPS release assets,
installs with lifecycle scripts disabled, rebuilds only better-sqlite3, and
runs typecheck, tests, and the read-only pre-start doctor. No wallet is funded
and no chain write, setup, purchase, payment, or fulfilment is authorized.

Source validation on the exact commit:

  • GitHub CI: Node 20.19 and Node 22 passed.
  • Secret scan and reproducible package/Bun consumer checks passed.
  • Core: 114 test files passed, 7 skipped; 2,983 tests passed.
  • Node host: 51 test files passed, 1 skipped; 346 tests passed.
  • Generator: 11 tests passed.
  • Package lifecycle and exact-version release-set verification passed.

Known preview boundaries:

  • PR #190 and its correctness dependencies must still be reviewed and merged.
  • Official npm publication remains protected and is intentionally not bypassed.
  • The current Demos SDK production tree retains 66 audit findings in a clean
    generated consumer; issue #191 tracks the required upstream package split.
  • Live setup/purchase remains guarded by explicit caps and per-invocation
    confirmation. Fresh generation is read-only and doctor-blocked until separate
    buyer/seller keys, databases, authorities, rail/listing configuration, and
    funding are supplied.
  • Use https://dev.node2.demos.sh while the normal Demos endpoint is unhealthy.