Skip to content

HIVE v1.0.1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 21:04
· 15 commits to main since this release
9f76ee1

HIVE v1.0.1 release notes

Status: Published stable release.

v1.0.1 is a bounded bugfix/maintenance release candidate prepared from the
approved HIVE main base. It has not been published, no v1.0.1 tag has been
created, and no GitHub Release exists as a result of this preparation.

Fixed

  • Windows local setup now keeps durable HIVE state at the recommended
    D:/HIVE root and user repositories at the separate D:/Projects root.
  • Project Registry values remain POSIX-relative paths below the mounted
    /workspace/projects boundary; absolute Windows host paths are rejected
    before Control Center submission.
  • Project source remains mounted read-only and is never used as writable HIVE
    state.
  • A registered project directory must be a real Git repository with at least
    one commit and a resolvable HEAD; plain folders and empty repositories are
    reported as degraded.

Scope and compatibility

This release adds no product capability and no database/schema migration. The
current migration head remains 0007_telemetry_events. PostgreSQL remains the
canonical durable store, Redis remains reconstructible hot cache state, and Git
remains the canonical source history.

Dependency security

The current paginated GitHub Dependabot inventory was collected with the
authenticated, non-secret command:

gh api --paginate --slurp "repos/KayzenRoot/hive/dependabot/alerts?state=open&per_page=100"

The inventory contains 3 open MEDIUM alerts, all development-only: alert 1 for
@vitest/mocker, alert 2 for vitest, and alert 6 for pytest. There are no
open CRITICAL or HIGH alerts applicable to this candidate, no LOW alerts, and
no dependency upgrade is required for this bounded bugfix. The complete
non-secret dispositions and candidate-manifest hash binding are recorded in
.engineering/release/HIVE-V1.0.1-SECURITY-TRIAGE.json.

Upgrade

Back up PostgreSQL and HIVE_DATA_ROOT, record the deployed commit, read these
notes and run the validation checks before restarting. Use the clean source
upgrade and Compose procedures in UPGRADING.md. This release
contains no migration-specific upgrade step.

Rollback

Stop Compose, restore the previous stable source revision v1.0.0, restore the
PostgreSQL and HIVE_DATA_ROOT backups if required, then start Compose and run
the health and integration checks described in UPGRADING.md.

Known limitations

  • The three remaining dependency alerts are development-only MEDIUM findings;
    they require a future major upgrade of the affected development tools.
  • Deterministic embedding, reranking and token benchmarks prove contract
    mechanics rather than production model quality.
  • Source distribution remains the supported channel; no container image, npm
    package or binary distribution is produced.
  • Tag signing, SBOM generation and build-provenance attestations are not
    claimed.

Validation expectations

Before Sol audit, the exact candidate head must pass release metadata
verification, deterministic validation, the backend and dashboard checks,
npm audit at the CI threshold, Docker Compose configuration and the supported
integration-health workflow. Review Evidence must confirm the exact base,
bounded paths, candidate security evidence and an unarmed publication state.

Security triage: .engineering/release/HIVE-V1.0.1-SECURITY-TRIAGE.json.