rqwstr v2.0.0
Public distribution build (binaries + .mcpb bundles + checksums). Source stays private; these binaries carry the embedded verification key.
Breaking (since v1.2.0)
- Fail-closed scope —
send,send_h2,chain, redirect hops,intruder,race,parallel, and sharedsession_setuprequire an enabled include rule (or[scope].unrestricted = true). hunt.scope_fileremoved — use[scope].file = "scope-policy.json"in server config.- Operator-file proxy lock, connection identity pinning, pre-wire authority checks, OOB destination lock.
fetchresult — top-levelidremoved; useexchange_id. Input parameter remainsid.
Upgrade
- Set an include rule (or intentional unrestricted) before upgrading clients.
- Move
hunt.scope_file→[scope].file. - Read
exchange_idfromfetchresults. - Install from these
v2.0.0assets (or https://rqwstr.com/static/releases/latest/).
rqwstr --version # expect: rqwstr 2.0.0
rqwstr setup # free activation still required for tool execution
Discovery-only tools/list without a license is unchanged (marketplace scanners).