Skip to content

Coven v0.4.1

Choose a tag to compare

@github-actions github-actions released this 28 Aug 15:29
· 94 commits to main since this release
v0.4.1
d07302c

Coven v0.4.1

Provider-owned setup for the three supported harnesses, deterministic GitHub
releases, and a substantially hardened release-reliability story. 81 commits
since v0.4.0.

Setup and onboarding

  • coven setup <codex|claude|copilot> performs provider-owned login with
    explicit consent, never proxying, copying, persisting, or redacting provider
    credentials. Fails closed outside a TTY.
  • --verify-only --report-json emits a redacted certification report carrying
    only harness, cli_version, platform, candidate_commit, duration, exit_class
    and completed -- no output, account data, tokens, or private paths.
  • Progressive public help, a reshaped first-session journey, and reconciled
    onboarding, auth and Doctor guidance.

Release engineering

  • GitHub Releases are now produced deterministically by workflow, with four
    platform archives plus SHA256SUMS, gated on re-verified npm provenance and
    signed-tag ancestry.
  • The operator runbook documents fresh-consumer install verification, the
    certification packet, and tag immutability.

Reliability

  • Cross-platform workspace suites now include macOS, which previously had no
    CI coverage.
  • Bounded release-stress loops run on Linux, macOS and Windows.
  • Hermetic three-harness contract parity proves prompt, model, permission,
    add-directory, continuity, persistence and exit behaviour stay in step
    across Codex, Claude Code and Copilot CLI.
  • Several load-sensitive wall-clock flakes fixed, with the classification rule
    recorded so the pattern stops recurring.

Fixes

  • Dependency audit unblocked past the yanked chacha20 0.10.1.
  • Relay queued-memory bounds and slow-peer timeouts.
  • Mobile pairing v2 re-landed transcript-bound.

Known gaps, recorded deliberately

  • The three-account certification packet was waived for this tag at the
    release owner's direction; it was not produced.
  • docs/reference/release-notes.md carries no v0.4.1 entry; these annotation
    notes are the release record.
  • Harness parity runs on Unix only; Windows executable resolution is covered
    separately.
    -----BEGIN SSH SIGNATURE-----
    U1NIU0lHAAAAAQAAADMAAAALc3NoLWVkMjU1MTkAAAAguzqcpSw/45XOhNc1hxn3wh4+l3
    iP5p67B5VL9yjNXwMAAAADZ2l0AAAAAAAAAAZzaGE1MTIAAABTAAAAC3NzaC1lZDI1NTE5
    AAAAQEXkkMM3qejzlZZxJvVODzY/qPqqWfK04jwilA5gWQHwDXsnbOOaAFK3hNRcbbLPi/
    wHtb+bJ09IF1O+I3EVhgA=
    -----END SSH SIGNATURE-----