Skip to content

Releases: Julio-Patron/tempus-ddb

v0.5.3 — Release Pipeline Repair (first published 0.5.2 security line)

Choose a tag to compare

@Julio-Patron Julio-Patron released this 26 Sep 10:53
1358831

First published build of the 0.5.2 security line.

The v0.5.2 release workflow failed before building any artifact, so 0.5.2 was never published to PyPI or crates.io. 0.5.3 ships the same runtime code (all 0.5.2 security remediations: delegation chain verification, signed policy activation, segregation of duties, Gate-DB revocation checks for executors, atomic state/stream mutations) with a repaired release pipeline.

Fixed

  • Release pipeline: four action pins in release.yml referenced commit SHAs that don't exist upstream. All pins now resolve to real tags.
  • Tag-exact builds: each release job checks out the release tag.
  • PyPI: publishes through Trusted Publishing (OIDC) only.
  • crates.io: first publication, from a separate job that uses the configured token.

Changed

  • Packaged sources no longer include the launch/ drafts.
  • python-dotenv>=1.2.3.

Install: python -m pip install tempus-ddb==0.5.3

Full details in CHANGELOG.md.

v0.5.2 — Security Remediations & Repository Stabilization

Choose a tag to compare

@Julio-Patron Julio-Patron released this 15 Sep 01:36

Tempus DDB v0.5.2 — Security Remediations & Repository Stabilization

Security & Invariants Hardening

  • Delegation Chain & Trusted Root Verification (Finding 1): Added trusted_roots enforcement with single-root constraint; enforce recursive delegation chain checks ensuring all registered identities trace to an established root authority (src/b2a.rs).
  • Signed Policy Activation & Strict Fallback (Finding 2): Added active_policy_attestations table storing cryptographic attestations over active policies; retired tenant policies fail closed instead of falling back to unconstrained wildcards; SSRF protection and destination domain allowlisting in http_executor (src/phase3.rs, python/tempus_ddb/http_executor.py).
  • Segregation of Duties & Role Enforcement (Finding 3): Prohibit proposing agents from executing their own permits (executor_id != agent_id); reject proposer roles from executor duty; enforce executor tenant scope matching (src/b2a.rs, src/phase3.rs, python/tempus_ddb/mcp_server.py).
  • Durability & Replay Defense Across Gate/Executor (Findings 4 & 6): Upgraded SQLite persistence to PRAGMA synchronous = FULL; across gate and executors; executors cross-verify revocation and consumption state against Gate DB before effectuating actions (src/b2a.rs, src/executor.rs).
  • Financial Policy Beneficiary Validation (Finding 5): Enforce allowed_beneficiaries pattern matching in both policy evaluation and payment execution (src/phase3.rs, python/tempus_ddb/payment_executor.py).
  • Untrusted Signer Rejection in Checkpoint Verification (Finding 7): Checkpoint stream verifier requires trusted public key and rejects checkpoints signed by arbitrary keys with ERR_UNTRUSTED_SIGNER (src/events.rs, src/lib.rs).
  • Atomic State and Stream Mutations (Finding 8): Wrapped policy installations, authorizations, and outcome commits in immediate atomic SQLite transactions to eliminate race conditions between mutation and audit event logging (src/b2a.rs, src/events.rs).
  • Workflow Hardening (Finding 9): Pinned all GitHub Actions in .github/workflows/release.yml to immutable commit SHAs; added automated wheel testing and cargo test gates prior to release publication.

Platform & Stability Improvements

  • Windows CP1252 Compatibility: Replaced all console and comment non-ASCII symbols with clean ASCII characters to prevent encoding crashes on Windows consoles (python/tempus_ddb/cli.py, python/tempus_ddb/mcp_server.py).
  • CI Test Matrix: Expanded CI test matrix to include Python 3.10, 3.11, and 3.12 across Ubuntu, macOS, and Windows.
  • Documentation & Site Synchronization: Synchronized compatibility matrices, security policies, documentation references, and demo scripts to v0.5.2.

v0.5.0 — Durable Local Operations & Checkpoints

Choose a tag to compare

@Julio-Patron Julio-Patron released this 06 Sep 03:39

Added

  • Append-Only Event Stream (\ empus.event-stream-event.v1): Monotonically sequenced, hash-linked (\prev_event_hash\ ➔ \�vent_digest) event recording for all authorizations, outcomes, agent registrations, and policy installations.
  • Signed Monotonic Checkpoints (\ empus.checkpoint.v1): Gate-signed external checkpoints binding cumulative SHA-256 stream root hashes and sequence windows (\ irst_sequence..\last_sequence).
  • Cryptographic Stream Verifier (\ empus.checkpoint-verification.v1): Offline mathematical verification engine detecting rollback attacks (\ERR_ROLLBACK_DETECTED), sequence gaps (\ERR_SEQUENCE_GAP), broken chain linkage (\ERR_CHAIN_LINKAGE_BROKEN), and single-byte tampering (\ERR_EVENT_TAMPERED).
  • Unified Mediated Executor Runtime (\ExecutorRuntime): Standardized base runtime with protocol \ActionAdapter\ and conformance testing harness (\AdapterConformanceHarness\ in \ empus_ddb.testing).
  • CLI Checkpoint & DR Commands: Added \ empus checkpoint create, \ empus checkpoint export, and \ empus checkpoint verify.
  • Disaster Recovery Guide: Published comprehensive procedures in \docs/BACKUP_AND_DISASTER_RECOVERY.md.

v0.4.2 - Pluggable Executors, RBAC Gateway Differentiation & Verification

Choose a tag to compare

@Julio-Patron Julio-Patron released this 31 Aug 10:53

Release 0.4.2

  • 4 Packaged Mediated Executors: Added \ empus-http-executor\ (HTTPS webhooks), \ empus-slack-executor\ (Slack alerts), \ empus-payment-executor\ (pluggable financial transport & money contract enforcement), and \ empus-github-executor.
  • Framework Cookbooks: Added integration recipes for LangChain/LangGraph, CrewAI, and Cursor/Claude Desktop MCP.
  • Architectural Differentiation: Added explicit comparison vs traditional RBAC/MCP proxies (Bifrost, Obot, MCPX, MintMCP).
  • Security & Integrity: Security policy alignment, SPDX SBOM, and Sigstore provenance attestations on all native artifacts.
  • PyPI Release: Native wheels published for Linux, macOS (x86_64 and arm64), and Windows.

v0.4.1 - Packaged Executors & RBAC Gateway Differentiation

Choose a tag to compare

@Julio-Patron Julio-Patron released this 31 Aug 08:04

Release 0.4.1

  • 4 Packaged Mediated Executors: Added \ empus-http-executor\ (HTTPS webhooks), \ empus-slack-executor\ (Slack alerts), \ empus-payment-executor\ (money contract enforcement), and \ empus-github-executor.
  • Framework Cookbooks: Added integration recipes for LangChain, CrewAI, and Cursor/Claude Desktop MCP.
  • Architectural Differentiation: Added explicit comparison vs traditional RBAC/MCP proxies (Bifrost, Obot, MCPX, MintMCP).
  • PyPI Release: Native wheels published for Linux, macOS, and Windows.

Tempus DDB v0.4.0

Choose a tag to compare

@Julio-Patron Julio-Patron released this 28 Aug 05:26

First public beta of the fail-closed B2A security gate for autonomous agent actions. Includes signed policy bundles, workload identity lifecycle, credential-isolated GitHub execution, and verifiable execution receipts.\n\nThis beta is validated across Python 3.10 and 3.12 on Linux, macOS, and Windows. It is intended for single-instance deployments; independent external checkpoints and multi-instance durability remain future work.