Skip to content

Releases: SoonGwan/open-aegis

Release list

Open Aegis 1.0.0

Choose a tag to compare

@SoonGwan SoonGwan released this 06 Oct 05:06
7922238

Open Aegis 1.0.0 is a self-hosted, MIT-licensed security validation workspace connecting authorized assets, reviewed plans, separate execution approval, recorded evidence and independent retests.

It includes a Korean React console; SQLite and optional PostgreSQL16; scoped configuration checks; goals, shared planning todos and Worker dependencies; task templates/categories/archives; versioned prompts; fixed webhooks; reviewed model profiles, explicit OpenAI/direct Claude text protocols, catalog and connection receipts; task model pins and unknown-request recovery; read-only/local and scoped remote MCP; audit/checkpoint, backup/restore and update-preflight tools.

Named integration values now load correctly in both local .env startup and Compose. Container port/data/UI paths stay fixed, literal dollar values survive, and MCP initialize reports the actual installed package version. Changes preserve schema2 and the dependency locks.

Validation: frozen 1.0.0 application native suite2,033 passed/2 owner-only SQLite skips; independent installed regression843 passed/2 skips; the added real-launch subprocess case and actual v1 HTTP configuration passed. Both-store record-preserving version transitions, startup-fault rollback, signature/tamper/preflight and installed runtime/UI/eight maintenance commands passed. Final combined PR checks completed all six. Main run37414561840 at79222383a6aa55cb3e07f0fd7151c1d3aec1bb79 also completed all six checks; metadata and full logs are retained.

The signed bundle contains the wheel, built UI and both dependency locks. Node.js is not needed to run that bundle. Verify the archive's detached Ed25519 signature before extraction and then verify its internal manifest before installing. Obtain the publisher key through a trusted channel; the checksum file alone does not authenticate the download.

Wheel SHA-256:
3cbbb80d21d0f84af2e368cff2711e122dba7d81a782e2e58a284d2b01008311

Publisher key SHA-256 of DER SubjectPublicKeyInfo:
7397518bca29defa1c665ae899bbb1592d0916bf79a8aca85308b74e77711176

This is an independently written project. Complete ARTEX parity, every vulnerability class, full mobile/screen-reader coverage, an independent security audit, commercial-provider billing validation, production SLO/PITR or external hosting of the application backend are not claimed. Updates require stopped-service preflight/backup and fresh review of plans bound to earlier code; preserve historical records rather than editing stored approvals.

Post-publication check: all five assets downloaded anonymously with HTTPS200 and matching hashes. The downloaded archive signature and internal signed manifest/payloads verified successfully.