Skip to content

Releases: KayzenRoot/hive

HIVE v1.0.3

Choose a tag to compare

@github-actions github-actions released this 24 Sep 09:02
52bd3da

HIVE v1.0.3 release notes

Status: Published stable release.

v1.0.3 is a backward-compatible PATCH candidate prepared from protected HIVE
main after the published v1.0.2 release. It documents the WO-031 changes
already present on main; it does not reimplement them or begin the Decision
Fabric 1.1 roadmap. Preparation base: 05e48e74fe4655e49eda5699458d50282428ee40.

Included

  • Hardened Windows installation and upgrade paths. Installation preserves an
    existing .env and refuses to treat a non-empty data root as a new install;
    Settings tests use deterministic environment isolation.
  • Added bounded automatic discovery under the configured
    HIVE_PROJECTS_ROOT. Discovery examines immediate child Git repositories,
    registers and inspects them, indexes new or changed repositories, and syncs
    them into retrieval. Duplicate physical identity and unsafe paths remain
    fail-closed. Missing projects become OFFLINE; registry records and source
    data are not deleted.
  • Improved the Windows D:/Projects host-root workflow through the Compose
    read-only mount at /workspace/projects.
  • Context, cache and executor telemetry is produced by real operations and
    persisted through the existing PostgreSQL telemetry infrastructure.
  • Improved the read-only Control Center project selection, KPI provenance and
    live/near-live refresh behavior, along with integration diagnostics and
    closure reporting.

Security and dependencies

The authenticated GitHub Dependabot inventory was collected on 2026-09-23
against preparation base 05e48e74fe4655e49eda5699458d50282428ee40. It contains
zero open CRITICAL, zero HIGH, one MODERATE and zero LOW alerts. The only open
alert is development-only pytest in requirements-dev.txt (GitHub severity
medium, GHSA-6w46-j5rx-g56g / CVE-2025-71176, affected versions < 9.0.3,
first patched version 9.0.3). There are no runtime alerts and no unresolved
applicable CRITICAL/HIGH alerts. The development-only pytest alert is retained;
this patch does not upgrade an unrelated test dependency to a new major line.

The release gate is PASS. The non-secret inventory and candidate manifest
hashes are recorded in
.engineering/release/HIVE-V1.0.3-SECURITY-TRIAGE.json.

Compatibility

  • No database migration is introduced; the migration head remains
    0007_telemetry_events.
  • PostgreSQL remains canonical durable state. Redis remains a reconstructible,
    non-canonical hot cache.
  • Optional provider metrics are not claimed as EXACT without provider evidence.
    Unknown values are not represented as zero, and no fake/demo metric claim is
    made.
  • No Docker volume reset is required.

Upgrade

Supported source: v1.0.2. Target: v1.0.3.

Before upgrading, back up PostgreSQL and HIVE_DATA_ROOT, and record the
currently deployed revision. Follow UPGRADING.md; rebuild the
Compose images and run the documented health checks after updating. Do not use
docker compose down -v.

Automatic discovery is enabled by default with
HIVE_AUTO_DISCOVERY_ENABLED=true; it scans every 60 seconds by default
(HIVE_AUTO_DISCOVERY_INTERVAL_SECONDS, range 10-3600) and examines at most
200 projects per scan (HIVE_AUTO_DISCOVERY_MAX_PROJECTS, range 1-1000). It can
be disabled with HIVE_AUTO_DISCOVERY_ENABLED=false. HIVE_PROJECTS_ROOT
defaults to .hive-projects outside Compose; Compose mounts the configured host
root read-only at /workspace/projects. For the documented Windows host-root
workflow, set HIVE_PROJECTS_ROOT=D:/Projects in .env. No destructive data
change or manual registry cleanup is required; discovery uses the existing
registry and leaves missing project records intact.

Rollback

Classification: SAFE_DIRECT.

WO-031 introduces no migration or schema change. Automatic discovery writes
project, index and retrieval state through the existing PostgreSQL structures;
it does not delete canonical rows or source data. The v1.0.2 code uses those
same structures, so the previous binary can read the unchanged schema and
additive registry state. This classification is based on the unchanged schema
and existing storage contracts; no rollback runtime exercise is claimed.

To roll back, stop Compose, restore source revision v1.0.2, rebuild and restart
the services, then run the documented health checks. Keep PostgreSQL and
HIVE_DATA_ROOT; a restore is not normally required for schema compatibility,
but retain the pre-upgrade backups in case operational recovery needs them. Do
not reset Docker volumes.

Release governance

This candidate is prepared under HIVE-REL-009. Publication authorization is a
separate future increment; no v1.0.3 publish request, tag or GitHub Release is
included here.

Security triage:
.engineering/release/HIVE-V1.0.3-SECURITY-TRIAGE.json.

HIVE v1.0.2

Choose a tag to compare

@github-actions github-actions released this 22 Sep 16:51
8db3d24

HIVE v1.0.2 release notes

Status: Published stable release.

v1.0.2 is a backward-compatible bugfix, security-maintenance and executor
stabilization release prepared from protected HIVE main. It does not change
the database migration head and does not alter the completed V0.1 Project Brain.

Fixed

  • Executor execution identity is resolved once per run, preventing duplicate
    deterministic resolution work and misleading provider/LLM accounting.
  • Any failed declared test or validation command now makes the staged executor
    result fail closed.
  • Progressive Disclosure ignores domain/email false positives, including common
    modern TLDs, without weakening detection of qualified code symbols.
  • A concrete bounded OpenAI-compatible HTTP ExecutorAdapter is available through
    ExecutionOrchestrator.execute_configured(). It is disabled by default and
    requires explicit operator configuration.
  • Provider responses fail closed when malformed, oversized, model-mismatched or
    otherwise outside the bounded contract.
  • Remote executor endpoints require HTTPS; plaintext HTTP is accepted only for
    explicit local hosts.
  • Real local HTTP transport plus Docker/CLI end-to-end coverage proves the
    concrete dispatch path and truthful one-provider-call/one-LLM-call accounting.
    This evidence does not claim a live third-party credential/provider run.

Security and dependencies

  • Vitest was upgraded to 4.1.11, remediating the recorded Vitest and
    @vitest/mocker development-only MEDIUM advisories.
  • The recorded candidate inventory has zero applicable CRITICAL/HIGH findings
    and one remaining development-only MEDIUM pytest advisory. It is non-runtime
    and requires a future pytest major upgrade.
  • Complete non-secret release evidence is recorded in
    .engineering/release/HIVE-V1.0.2-SECURITY-TRIAGE.json.

Compatibility

  • Migration head remains 0007_telemetry_events.
  • PostgreSQL remains canonical durable structured state.
  • Redis remains reconstructible hot cache state.
  • Git remains canonical source history.
  • Existing local-only operation remains valid because executor transport is
    disabled by default unless explicitly configured.

Upgrade

Back up PostgreSQL and HIVE_DATA_ROOT, record the currently deployed
revision, then follow UPGRADING.md. No migration-specific
upgrade step is required for v1.0.2.

After updating, run the documented Compose health and integration checks before
normal use. Configure HIVE_EXECUTOR_* values only when a trusted compatible
executor endpoint is intended.

Rollback

Stop Compose, restore the previous stable source revision v1.0.1, restore
the PostgreSQL and HIVE_DATA_ROOT backups if required, then start Compose and
run the health/integration checks in UPGRADING.md.

Known limitations

  • One development-only MEDIUM pytest advisory remains recorded.
  • Concrete executor transport evidence uses a local HTTP fixture and does not
    claim a live external provider credential was exercised.
  • Deterministic embedding, reranking and token benchmarks prove contract
    mechanics rather than production model quality.
  • Source distribution remains the supported channel; no container image, npm
    package or binary distribution is produced.
  • Tag signing, SBOM generation and build-provenance attestations are not claimed.

Validation expectations

Before Sol audit, the exact candidate HEAD must pass release metadata
verification, deterministic validation, backend/dashboard checks, npm audit at
the CI threshold, Docker Compose configuration, Integration health and Review
Evidence. The later publication authorization remains a separate governed
increment.

Security triage: .engineering/release/HIVE-V1.0.2-SECURITY-TRIAGE.json.

HIVE v1.0.1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 21:04
9f76ee1

HIVE v1.0.1 release notes

Status: Published stable release.

v1.0.1 is a bounded bugfix/maintenance release candidate prepared from the
approved HIVE main base. It has not been published, no v1.0.1 tag has been
created, and no GitHub Release exists as a result of this preparation.

Fixed

  • Windows local setup now keeps durable HIVE state at the recommended
    D:/HIVE root and user repositories at the separate D:/Projects root.
  • Project Registry values remain POSIX-relative paths below the mounted
    /workspace/projects boundary; absolute Windows host paths are rejected
    before Control Center submission.
  • Project source remains mounted read-only and is never used as writable HIVE
    state.
  • A registered project directory must be a real Git repository with at least
    one commit and a resolvable HEAD; plain folders and empty repositories are
    reported as degraded.

Scope and compatibility

This release adds no product capability and no database/schema migration. The
current migration head remains 0007_telemetry_events. PostgreSQL remains the
canonical durable store, Redis remains reconstructible hot cache state, and Git
remains the canonical source history.

Dependency security

The current paginated GitHub Dependabot inventory was collected with the
authenticated, non-secret command:

gh api --paginate --slurp "repos/KayzenRoot/hive/dependabot/alerts?state=open&per_page=100"

The inventory contains 3 open MEDIUM alerts, all development-only: alert 1 for
@vitest/mocker, alert 2 for vitest, and alert 6 for pytest. There are no
open CRITICAL or HIGH alerts applicable to this candidate, no LOW alerts, and
no dependency upgrade is required for this bounded bugfix. The complete
non-secret dispositions and candidate-manifest hash binding are recorded in
.engineering/release/HIVE-V1.0.1-SECURITY-TRIAGE.json.

Upgrade

Back up PostgreSQL and HIVE_DATA_ROOT, record the deployed commit, read these
notes and run the validation checks before restarting. Use the clean source
upgrade and Compose procedures in UPGRADING.md. This release
contains no migration-specific upgrade step.

Rollback

Stop Compose, restore the previous stable source revision v1.0.0, restore the
PostgreSQL and HIVE_DATA_ROOT backups if required, then start Compose and run
the health and integration checks described in UPGRADING.md.

Known limitations

  • The three remaining dependency alerts are development-only MEDIUM findings;
    they require a future major upgrade of the affected development tools.
  • Deterministic embedding, reranking and token benchmarks prove contract
    mechanics rather than production model quality.
  • Source distribution remains the supported channel; no container image, npm
    package or binary distribution is produced.
  • Tag signing, SBOM generation and build-provenance attestations are not
    claimed.

Validation expectations

Before Sol audit, the exact candidate head must pass release metadata
verification, deterministic validation, the backend and dashboard checks,
npm audit at the CI threshold, Docker Compose configuration and the supported
integration-health workflow. Review Evidence must confirm the exact base,
bounded paths, candidate security evidence and an unarmed publication state.

Security triage: .engineering/release/HIVE-V1.0.1-SECURITY-TRIAGE.json.

HIVE v1.0.0

Choose a tag to compare

@github-actions github-actions released this 18 Sep 09:44
a53b5b9

HIVE v1.0.0 release notes

Status: Published stable release.

Summary

HIVE v1.0.0 is the first stable professional release of the product baseline
accepted internally as HIVE V0.1 — Foundation. It is a release-engineering,
maintenance-governance and repository-presentation promotion: the product
architecture, PostgreSQL/pgvector/Redis/CAS data model and the accepted V0.1
closure evidence are unchanged.

Highlights

  • Stable SemVer distribution identity 1.0.0 synchronized across VERSION,
    backend runtime surfaces and the dashboard package metadata.
  • Professional public repository presentation: README landing page, All Rights
    Reserved rights notice, CONTRIBUTING, SECURITY, SUPPORT, AGENTS, issue/PR
    templates and release/maintenance documentation.
  • Deterministic release metadata verification
    (scripts/verify_release_metadata.py) integrated into the mandatory Validate
    gate, failing closed on version/notes/CHANGELOG/README drift.
  • Hardened release workflow: annotated-tag identity, exact tag/VERSION match,
    release-note and CHANGELOG coherence, full validation and integration smoke on
    the tag commit, deterministic ZIP + SHA256 + machine-readable release manifest.
  • Release-candidate provenance receipt under .engineering/release/ recording
    the immutable V0.1 closure lineage without fabricating post-publication values.
  • Weekly grouped Dependabot cadence (pip, npm, GitHub Actions) with breaking
    majors kept separately reviewable and dependency PRs never auto-merged.
  • CodeQL analysis (Python, JavaScript/TypeScript) and Dependency Review on pull
    requests; both are advisory-only in this increment and are not ruleset checks.

The capability set below is the accepted V0.1 baseline and is documented in the
canonical Project Brain sources rather than duplicated here:

  • Durable Project Registry, task/prompt intake with content-addressed original
    preservation (SHA-256 + lossless Zstandard), Git-aware incremental repository
    indexing with Python AST symbol metadata.
  • Project-scoped lexical, semantic (pgvector) and hybrid RRF retrieval with
    provider-independent embedding adapters, optional reranking and deterministic
    fallback behavior.
  • Checkpoint-first Context Manager, progressive disclosure (L0–L5), adaptive
    token budgeting, context fingerprints, delta context and provider/prompt cache
    adapters, over durable memory with provenance and lifecycle.
  • Governed autonomous execution foundation (tool gating, staged noncanonical
    output, local verified runner), MCP read-only core surface, telemetry/event
    bus and the full HIVE Control Center.
  • Local Docker Compose deployment, backup/recovery and secondary-disk
    persistence.

Fixed

  • Removed stale pre-alpha/bootstrap positioning from the repository
    presentation and active version surfaces.
  • Release package verification now fails closed on missing required stable
    release files and on forbidden secret/local paths.

Security

  • No secrets, credentials, keys, .env files or user runtime data are included
    in the release diff or package; scripts/check_secrets.py remains mandatory
    and is not weakened.
  • GitHub secret scanning and push protection are enabled; CodeQL and Dependency
    Review are added as advisory security automation in this increment.
  • Dependency security: all 16 open HIGH Dependabot advisories on the default
    branch are remediated in this candidate by pinned patched versions —
    fastapi==0.133.0 (enabling starlette==1.3.1), python-multipart==0.0.31
    and Mako==1.3.12 — covering both runtime and development manifests. The
    bounded receipt is
    .engineering/release/HIVE-V1.0.0-SECURITY-TRIAGE.json with
    release_gate = PASS and runtime_high_critical_remaining = false.
  • Remaining open dependency alerts are MEDIUM and development-only
    (vitest/@vitest/mocker and pytest); they have no runtime exposure, are
    not hidden and are recorded in the triage receipt. GitHub may keep the
    remediated alerts open on main until this candidate is merged.
  • Project isolation, provenance and fail-closed security behavior are covered by
    the accepted V0.1 evidence; product defect counts (HIGH/CRITICAL 0/0) are
    distinct from dependency advisories and are not used to claim dependency
    security.

Compatibility

  • The supported line starts at 1.0.x; public API, schema and operational
    contract begin with this release, so no compatibility break relative to any
    published release exists.
  • Migration head is 0007_telemetry_events. This increment introduces no
    migrations.

Upgrade

See UPGRADING.md. Upgrading from the historical bootstrap
pre-release is a clean source upgrade with a backup of PostgreSQL and
HIVE_DATA_ROOT; no release-specific migration step is required for v1.0.0.

Rollback

Roll back by redeploying the previous revision (v0.0.1-bootstrap for the
historical pre-release) and restoring the pre-upgrade PostgreSQL and data-root
backups as described in UPGRADING.md.

Known limitations

  • Deterministic embedding, rerank and token benchmarks prove contract mechanics,
    not production model quality; no local embedding model or local reranker is
    promoted.
  • Exact provider token, cost and cache-hit values remain unavailable without
    provider receipts and are never rendered as zero.
  • Source release is the required distribution channel; no container-image,
    npm-package or binary distribution exists in this increment.
  • Tag signing, SBOM generation and build-provenance attestations are not
    claimed.
  • Three MEDIUM development-only dependency alerts remain open and are documented
    in the security triage receipt; there are no remaining LOW alerts.
  • The fastapi/starlette upgrade introduces one non-blocking
    StarletteDeprecationWarning about httpx in starlette.testclient
    (httpx2 migration is deferred to dependency maintenance).
  • Historical v0.0.1-bootstrap notes and the internal V0.1 Foundation history
    remain as originally accepted and are not rewritten.

Validation evidence

Exact validation, integration health, security and Review Evidence results are
recorded for the audited release-preparation head in the PR Review Evidence and
the .engineering/release/HIVE-V1.0.0-RELEASE-CANDIDATE.json receipt. The
dependency alert inventory and dispositions are recorded in
.engineering/release/HIVE-V1.0.0-SECURITY-TRIAGE.json. The accepted product
closure evidence remains DoD 46/46 PASS, 0 FAIL, 0 UNKNOWN, HIGH/CRITICAL 0/0.

Checksums and artifacts

hive-v1.0.0.zip, hive-v1.0.0.zip.sha256 and
hive-v1.0.0.manifest.json are generated deterministically by the release
workflow from the exact tag commit. They do not exist before publication and are
not fabricated here; verify them against the published GitHub Release assets.

Lineage

  • Accepted V0.1 product closure: PR #95, audited head
    649e7f90fc4f2d4e3cbc17ca0f38d5f2c9dd46ad, Sol review 5233591627, squash
    merge 05d142511f849d002c4ec8558fe4f43dca3e788b, post-merge CI
    35204484706.
  • Final promotion: PR #98, audited head
    1e480a815da16276a57fa85ee7c1eb9ef87adc41, final main
    90cc1b91b48d628dfb3e4773e1672535b4cb8991, post-merge CI 35278763114.
  • Release preparation: HIVE-REL-001 / issue #105, branch
    release/v1.0.0-professionalization, authorized base
    90cc1b91b48d628dfb3e4773e1672535b4cb8991.

HIVE v0.0.1-bootstrap

HIVE v0.0.1-bootstrap Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 31 Aug 16:59
8596769

HIVE v0.0.1-bootstrap draft release notes

Status: draft pre-release. Do not publish before Sol approval.

Included

  • Canonical HIVE project source pack and repository governance.
  • Local Docker Compose foundation with PostgreSQL/pgvector and Redis.
  • Minimal FastAPI health endpoint with real PostgreSQL, pgvector, Redis, and
    data-root checks.
  • TypeScript React dashboard that renders real API health data.
  • Cross-platform installation, troubleshooting, upgrade, release, and audit
    documentation.
  • Backend and dashboard validation, CI, release workflow preparation, and
    deterministic review bundle generation.

Explicitly not included

RAG, embeddings, reranking, production Context Manager, persistent HIVE memory
semantics, complete MCP capability surface, autonomous executor dispatch, full
Control Center telemetry, Docker image publication, and the public release
itself.

Validation

Final validation results belong to the generated review bundle and must be
reviewed before this draft is promoted.