Skip to content

korg v0.2.0

Latest

Choose a tag to compare

@New1Direction New1Direction released this 05 Oct 08:25
· 1 commit to main since this release
4029b92

korg is a tamper-evident, SHA-256-chained ledger for AI agents. This release turns it into something you can hand to someone else: capture a session, mint it into a signed Certificate, and let anyone re-verify it offline with zero trust in you or in korg.

Highlights

  • Zero-config capture for Claude Code. korg-setup installs a hook that writes one verifiable ledger per session under ~/.korg/sessions/. korg-backfill captures your past transcripts too.
  • korgcert@v1 Certificates. korg-seal mint session.jsonl --claim "..." produces a signed certificate whose human-readable summary (files touched, tools used, steps) is re-derived from the events at verify time, so it cannot lie. Three conformant verifiers (Rust, Python, JS) plus a zero-install browser verifier at https://new1direction.github.io/korg/.
  • Trusted time. korg-seal anchor binds a public git commit as a witness; korg-seal resolve proves the chain existed no later than that commit.
  • Verify in CI. The verify-korgcert GitHub Action fails a job on a tampered or unpinned artifact and posts the attestation as a sticky PR comment.
  • An honest swarm. Workers apply real patches in git worktrees and the ledger attests the real diff, never synthetic numbers. korg run-once --provider ollama runs the pipeline on a real local model.
  • Cross-vendor capture (N=3). Adapters for Claude Code, OpenAI Codex CLI and Grok Heavy, plus recall-mcp for cross-session memory and introspect-mcp to expose any --introspect binary as MCP tools.
  • Hardened. Three adversarial bug-hunt passes fixed 32 real bugs, including a receipt-signature forge and a JS canonicalization divergence. Verifiers are fuzzed and differentially tested across all three implementations with 0 divergences.

Breaking change

The certificate format goldseal@v1 is renamed korgcert@v1. Seals minted under the old name must be re-minted.

Try it in 30 seconds

See the quickstart: build korg-verify, verify a real session ledger, edit one event, and watch the verifier name it.

Downloads

Prebuilt korg binaries for Linux x86_64 (glibc), macOS x86_64 and arm64, and Windows x86_64 are attached below.

Full details: CHANGELOG.md · Compare: v0.1.0...v0.2.0