Skip to content

HIVE v1.0.2

Choose a tag to compare

@github-actions github-actions released this 22 Sep 16:51
· 7 commits to main since this release
8db3d24

HIVE v1.0.2 release notes

Status: Published stable release.

v1.0.2 is a backward-compatible bugfix, security-maintenance and executor
stabilization release prepared from protected HIVE main. It does not change
the database migration head and does not alter the completed V0.1 Project Brain.

Fixed

  • Executor execution identity is resolved once per run, preventing duplicate
    deterministic resolution work and misleading provider/LLM accounting.
  • Any failed declared test or validation command now makes the staged executor
    result fail closed.
  • Progressive Disclosure ignores domain/email false positives, including common
    modern TLDs, without weakening detection of qualified code symbols.
  • A concrete bounded OpenAI-compatible HTTP ExecutorAdapter is available through
    ExecutionOrchestrator.execute_configured(). It is disabled by default and
    requires explicit operator configuration.
  • Provider responses fail closed when malformed, oversized, model-mismatched or
    otherwise outside the bounded contract.
  • Remote executor endpoints require HTTPS; plaintext HTTP is accepted only for
    explicit local hosts.
  • Real local HTTP transport plus Docker/CLI end-to-end coverage proves the
    concrete dispatch path and truthful one-provider-call/one-LLM-call accounting.
    This evidence does not claim a live third-party credential/provider run.

Security and dependencies

  • Vitest was upgraded to 4.1.11, remediating the recorded Vitest and
    @vitest/mocker development-only MEDIUM advisories.
  • The recorded candidate inventory has zero applicable CRITICAL/HIGH findings
    and one remaining development-only MEDIUM pytest advisory. It is non-runtime
    and requires a future pytest major upgrade.
  • Complete non-secret release evidence is recorded in
    .engineering/release/HIVE-V1.0.2-SECURITY-TRIAGE.json.

Compatibility

  • Migration head remains 0007_telemetry_events.
  • PostgreSQL remains canonical durable structured state.
  • Redis remains reconstructible hot cache state.
  • Git remains canonical source history.
  • Existing local-only operation remains valid because executor transport is
    disabled by default unless explicitly configured.

Upgrade

Back up PostgreSQL and HIVE_DATA_ROOT, record the currently deployed
revision, then follow UPGRADING.md. No migration-specific
upgrade step is required for v1.0.2.

After updating, run the documented Compose health and integration checks before
normal use. Configure HIVE_EXECUTOR_* values only when a trusted compatible
executor endpoint is intended.

Rollback

Stop Compose, restore the previous stable source revision v1.0.1, restore
the PostgreSQL and HIVE_DATA_ROOT backups if required, then start Compose and
run the health/integration checks in UPGRADING.md.

Known limitations

  • One development-only MEDIUM pytest advisory remains recorded.
  • Concrete executor transport evidence uses a local HTTP fixture and does not
    claim a live external provider credential was exercised.
  • Deterministic embedding, reranking and token benchmarks prove contract
    mechanics rather than production model quality.
  • Source distribution remains the supported channel; no container image, npm
    package or binary distribution is produced.
  • Tag signing, SBOM generation and build-provenance attestations are not claimed.

Validation expectations

Before Sol audit, the exact candidate HEAD must pass release metadata
verification, deterministic validation, backend/dashboard checks, npm audit at
the CI threshold, Docker Compose configuration, Integration health and Review
Evidence. The later publication authorization remains a separate governed
increment.

Security triage: .engineering/release/HIVE-V1.0.2-SECURITY-TRIAGE.json.