Repository navigation
HIVE v1.0.2
HIVE v1.0.2 release notes
Status: Published stable release.
v1.0.2 is a backward-compatible bugfix, security-maintenance and executor
stabilization release prepared from protected HIVE main. It does not change
the database migration head and does not alter the completed V0.1 Project Brain.
Fixed
- Executor execution identity is resolved once per run, preventing duplicate
deterministic resolution work and misleading provider/LLM accounting. - Any failed declared test or validation command now makes the staged executor
result fail closed. - Progressive Disclosure ignores domain/email false positives, including common
modern TLDs, without weakening detection of qualified code symbols. - A concrete bounded OpenAI-compatible HTTP ExecutorAdapter is available through
ExecutionOrchestrator.execute_configured(). It is disabled by default and
requires explicit operator configuration. - Provider responses fail closed when malformed, oversized, model-mismatched or
otherwise outside the bounded contract. - Remote executor endpoints require HTTPS; plaintext HTTP is accepted only for
explicit local hosts. - Real local HTTP transport plus Docker/CLI end-to-end coverage proves the
concrete dispatch path and truthful one-provider-call/one-LLM-call accounting.
This evidence does not claim a live third-party credential/provider run.
Security and dependencies
- Vitest was upgraded to 4.1.11, remediating the recorded Vitest and
@vitest/mockerdevelopment-only MEDIUM advisories. - The recorded candidate inventory has zero applicable CRITICAL/HIGH findings
and one remaining development-only MEDIUM pytest advisory. It is non-runtime
and requires a future pytest major upgrade. - Complete non-secret release evidence is recorded in
.engineering/release/HIVE-V1.0.2-SECURITY-TRIAGE.json.
Compatibility
- Migration head remains
0007_telemetry_events. - PostgreSQL remains canonical durable structured state.
- Redis remains reconstructible hot cache state.
- Git remains canonical source history.
- Existing local-only operation remains valid because executor transport is
disabled by default unless explicitly configured.
Upgrade
Back up PostgreSQL and HIVE_DATA_ROOT, record the currently deployed
revision, then follow UPGRADING.md. No migration-specific
upgrade step is required for v1.0.2.
After updating, run the documented Compose health and integration checks before
normal use. Configure HIVE_EXECUTOR_* values only when a trusted compatible
executor endpoint is intended.
Rollback
Stop Compose, restore the previous stable source revision v1.0.1, restore
the PostgreSQL and HIVE_DATA_ROOT backups if required, then start Compose and
run the health/integration checks in UPGRADING.md.
Known limitations
- One development-only MEDIUM pytest advisory remains recorded.
- Concrete executor transport evidence uses a local HTTP fixture and does not
claim a live external provider credential was exercised. - Deterministic embedding, reranking and token benchmarks prove contract
mechanics rather than production model quality. - Source distribution remains the supported channel; no container image, npm
package or binary distribution is produced. - Tag signing, SBOM generation and build-provenance attestations are not claimed.
Validation expectations
Before Sol audit, the exact candidate HEAD must pass release metadata
verification, deterministic validation, backend/dashboard checks, npm audit at
the CI threshold, Docker Compose configuration, Integration health and Review
Evidence. The later publication authorization remains a separate governed
increment.
Security triage: .engineering/release/HIVE-V1.0.2-SECURITY-TRIAGE.json.