Coven v0.4.1
Coven v0.4.1
Provider-owned setup for the three supported harnesses, deterministic GitHub
releases, and a substantially hardened release-reliability story. 81 commits
since v0.4.0.
Setup and onboarding
coven setup <codex|claude|copilot>performs provider-owned login with
explicit consent, never proxying, copying, persisting, or redacting provider
credentials. Fails closed outside a TTY.--verify-only --report-jsonemits a redacted certification report carrying
only harness, cli_version, platform, candidate_commit, duration, exit_class
and completed -- no output, account data, tokens, or private paths.- Progressive public help, a reshaped first-session journey, and reconciled
onboarding, auth and Doctor guidance.
Release engineering
- GitHub Releases are now produced deterministically by workflow, with four
platform archives plus SHA256SUMS, gated on re-verified npm provenance and
signed-tag ancestry. - The operator runbook documents fresh-consumer install verification, the
certification packet, and tag immutability.
Reliability
- Cross-platform workspace suites now include macOS, which previously had no
CI coverage. - Bounded release-stress loops run on Linux, macOS and Windows.
- Hermetic three-harness contract parity proves prompt, model, permission,
add-directory, continuity, persistence and exit behaviour stay in step
across Codex, Claude Code and Copilot CLI. - Several load-sensitive wall-clock flakes fixed, with the classification rule
recorded so the pattern stops recurring.
Fixes
- Dependency audit unblocked past the yanked chacha20 0.10.1.
- Relay queued-memory bounds and slow-peer timeouts.
- Mobile pairing v2 re-landed transcript-bound.
Known gaps, recorded deliberately
- The three-account certification packet was waived for this tag at the
release owner's direction; it was not produced. - docs/reference/release-notes.md carries no v0.4.1 entry; these annotation
notes are the release record. - Harness parity runs on Unix only; Windows executable resolution is covered
separately.
-----BEGIN SSH SIGNATURE-----
U1NIU0lHAAAAAQAAADMAAAALc3NoLWVkMjU1MTkAAAAguzqcpSw/45XOhNc1hxn3wh4+l3
iP5p67B5VL9yjNXwMAAAADZ2l0AAAAAAAAAAZzaGE1MTIAAABTAAAAC3NzaC1lZDI1NTE5
AAAAQEXkkMM3qejzlZZxJvVODzY/qPqqWfK04jwilA5gWQHwDXsnbOOaAFK3hNRcbbLPi/
wHtb+bJ09IF1O+I3EVhgA=
-----END SSH SIGNATURE-----