Skip to content

HIVE v1.0.3

Latest

Choose a tag to compare

@github-actions github-actions released this 24 Sep 09:02
· 2 commits to main since this release
52bd3da

HIVE v1.0.3 release notes

Status: Published stable release.

v1.0.3 is a backward-compatible PATCH candidate prepared from protected HIVE
main after the published v1.0.2 release. It documents the WO-031 changes
already present on main; it does not reimplement them or begin the Decision
Fabric 1.1 roadmap. Preparation base: 05e48e74fe4655e49eda5699458d50282428ee40.

Included

  • Hardened Windows installation and upgrade paths. Installation preserves an
    existing .env and refuses to treat a non-empty data root as a new install;
    Settings tests use deterministic environment isolation.
  • Added bounded automatic discovery under the configured
    HIVE_PROJECTS_ROOT. Discovery examines immediate child Git repositories,
    registers and inspects them, indexes new or changed repositories, and syncs
    them into retrieval. Duplicate physical identity and unsafe paths remain
    fail-closed. Missing projects become OFFLINE; registry records and source
    data are not deleted.
  • Improved the Windows D:/Projects host-root workflow through the Compose
    read-only mount at /workspace/projects.
  • Context, cache and executor telemetry is produced by real operations and
    persisted through the existing PostgreSQL telemetry infrastructure.
  • Improved the read-only Control Center project selection, KPI provenance and
    live/near-live refresh behavior, along with integration diagnostics and
    closure reporting.

Security and dependencies

The authenticated GitHub Dependabot inventory was collected on 2026-09-23
against preparation base 05e48e74fe4655e49eda5699458d50282428ee40. It contains
zero open CRITICAL, zero HIGH, one MODERATE and zero LOW alerts. The only open
alert is development-only pytest in requirements-dev.txt (GitHub severity
medium, GHSA-6w46-j5rx-g56g / CVE-2025-71176, affected versions < 9.0.3,
first patched version 9.0.3). There are no runtime alerts and no unresolved
applicable CRITICAL/HIGH alerts. The development-only pytest alert is retained;
this patch does not upgrade an unrelated test dependency to a new major line.

The release gate is PASS. The non-secret inventory and candidate manifest
hashes are recorded in
.engineering/release/HIVE-V1.0.3-SECURITY-TRIAGE.json.

Compatibility

  • No database migration is introduced; the migration head remains
    0007_telemetry_events.
  • PostgreSQL remains canonical durable state. Redis remains a reconstructible,
    non-canonical hot cache.
  • Optional provider metrics are not claimed as EXACT without provider evidence.
    Unknown values are not represented as zero, and no fake/demo metric claim is
    made.
  • No Docker volume reset is required.

Upgrade

Supported source: v1.0.2. Target: v1.0.3.

Before upgrading, back up PostgreSQL and HIVE_DATA_ROOT, and record the
currently deployed revision. Follow UPGRADING.md; rebuild the
Compose images and run the documented health checks after updating. Do not use
docker compose down -v.

Automatic discovery is enabled by default with
HIVE_AUTO_DISCOVERY_ENABLED=true; it scans every 60 seconds by default
(HIVE_AUTO_DISCOVERY_INTERVAL_SECONDS, range 10-3600) and examines at most
200 projects per scan (HIVE_AUTO_DISCOVERY_MAX_PROJECTS, range 1-1000). It can
be disabled with HIVE_AUTO_DISCOVERY_ENABLED=false. HIVE_PROJECTS_ROOT
defaults to .hive-projects outside Compose; Compose mounts the configured host
root read-only at /workspace/projects. For the documented Windows host-root
workflow, set HIVE_PROJECTS_ROOT=D:/Projects in .env. No destructive data
change or manual registry cleanup is required; discovery uses the existing
registry and leaves missing project records intact.

Rollback

Classification: SAFE_DIRECT.

WO-031 introduces no migration or schema change. Automatic discovery writes
project, index and retrieval state through the existing PostgreSQL structures;
it does not delete canonical rows or source data. The v1.0.2 code uses those
same structures, so the previous binary can read the unchanged schema and
additive registry state. This classification is based on the unchanged schema
and existing storage contracts; no rollback runtime exercise is claimed.

To roll back, stop Compose, restore source revision v1.0.2, rebuild and restart
the services, then run the documented health checks. Keep PostgreSQL and
HIVE_DATA_ROOT; a restore is not normally required for schema compatibility,
but retain the pre-upgrade backups in case operational recovery needs them. Do
not reset Docker volumes.

Release governance

This candidate is prepared under HIVE-REL-009. Publication authorization is a
separate future increment; no v1.0.3 publish request, tag or GitHub Release is
included here.

Security triage:
.engineering/release/HIVE-V1.0.3-SECURITY-TRIAGE.json.