v1.0.0
The first published release since 0.15.0, on the advisory channel. It
publishes diff, check, audit --host, drift and advisory PR comments, and
makes no qualification claim. 0.16.0 was prepared but never published, so
everything in its section below ships here too.
The full reviewed prose is in
docs/changelog/1.0.0.md, and for the 0.16.0
line in docs/changelog/0.16.0.md. This section
is the release note; those files are the record.
Migration notes: read every Migration Note: 1.0.0 and
Migration Note: 0.16.0b* entry in STABILITY.md before
upgrading from 0.15.0. Several change a published schema or a contract
version.
Highlights
shipgate diffnames what a change does to an agent's authority: one row
per host grant, with no manifest and no committed baseline. (#651)- Host comparisons reach real repositories. In-tree links, documented
frontmatter, JSON with comments, Cursor globs, plugin marketplaces and
unchanged partial surfaces no longer refuse the comparison. (#700, #720,
#721, #722, #723, #729, #730, #731) - A narrowing is not an expansion. Tightening a rule no longer reads as a
widened allowlist, and a settings narrowing finishes without a human review.
(#657, #661) - The Claude Code hooks stay fast and quiet. The Stop hook compares host
configuration in under a second and repeats no advisory within a session.
(#661) - The control envelope names the change in a bounded
capability_rows
block, and the generated agent instructions lead with it. (#662) - Measured on the 1.0.0 candidate wheel, including where it falls short.
On the wheel Release Engine Smoke exercised on747d6080(1b846258…): ten pinned public
MCP servers gave 76 findings, 1 false (1.3%, bar under 2%); a fresh clone
reached a correct comparison in 26 of 30 public repositories (bar 24); on 50
public host-config PRs, row precision is 70 of 70, while widening recall
(55 of 65) and the benign zero-row rate (5 of 6) stay below their bars, with
every miss named in its run. (#658, #660, #659) - The report contract is frozen at
1.0. (#569) - An advisory version publishes through the ordinary release pipeline,
declared in.github/release-channels.json. (#648)
Changes
- Re-run the three live measurements on the wheel Release Engine Smoke exercised on
747d6080, after the last engine changes, as the runs of record; every outcome is unchanged. (#658, #659, #660) - Build the optional MCP server on the SDK 2.x
MCPServer, the API the[mcp]extra has installed since SDK 2.0, somcp-servestarts again. An SDK without it is named as a version problem, and CI installs the extra at its floor and its newest release. (#713) - Read Git pathnames that contain spaces in
check,verifyand the MCPchecktool. A change touchingdocs/new scope/notes.mdno longer asks for review of an invalid path, and no longer crashescheckwhen a manifest is configured. (#581) - Name step action references, named reusable-workflow secrets and remote MCP URL paths as unread host surfaces, say that a hook row does not prove the host loads the file, and state which symlinks refuse a comparison. (#693, #714, #771, #772)
- Preserve host permission-change semantics when
checkredacts rule arguments; scoped narrowing and widening now agree withdiffandverify. (#767) - Report incomplete coverage for malformed Claude permission containers and
allow/deny/askarrays instead of a covered no-change comparison. Unknown extension settings remain allowed. (#768) - Exercise the #659 oracle with positive, narrowing and neutral controls a bad engine fails, and record how its expectations are labelled. (#659)
- Give release verification's correctness suite a budget re-derived for today's suite, which had outgrown its 20 minutes. (#648)
- Re-run the three live measurements on the 1.0.0 candidate wheel as the runs of record, and refuse a committed run with an unmasked local path. (#658, #659, #660)
- Name composite actions and hook-run scripts as unread host surfaces on the support page. (#701, #702)
- Remove the runbook's manual undraft, which skipped every finalisation check; re-running
finalizeis the only recovery. (#618) - Make the release rehearsal's provenance drill reach the payload it tampers with, after an untouched control copy passes. (#615)
- Name every kind of host expansion in
preflight's explanation, with the total and what was folded. (#681) - Publish as
1.0.0on the advisory channel, state the1.xstability line, and keepcodex-boundary-jsonand legacy policy discovery through1.x. - Commit the ten-server MCP findings table: 76 findings, 1 false (1.3%), re-scored in CI against committed labels. (#658)
- Leave eval-harness and mock tools out of an MCP server's source catalog. (#658)
- Stop reading a topic as a contradiction of
readOnlyHint: only a modifying effect contradicts it, and a keyword inference also needs an action verb. (#658) - Stop reporting an MCP source description the reader cannot resolve as missing. (#658)
- Read
.vscode/mcp.jsonas JSON with comments. (#659) - Answer the Claude Code Stop hook's host comparison in under a second. (#661)
- Stop repeating hook advisories within a Claude Code session. (#661)
- Let a host settings narrowing finish without a human review. (#661)
- Document that
checkandverifypublish changed-file paths verbatim. (#742) - Read through an in-tree link at a boundary path (runtime contract 39, host-grants inventory
0.5). (#700) - Read Go MCP servers' literal tool hints for the contradiction check. (#658)
- Stop calling a narrowed allow rule an expanded allowlist in
checkandverify. (#661) - Keep credential-shaped bytes in a directory or file name out of host inventory output. (#590)
- Name the host capability change in the compact control envelope (runtime contract 38). (#662)
- Support
.vscode/mcp.jsonas a first-class host surface. (#731) - Digest undocumented skill and command frontmatter keys, and read a skill without frontmatter by its documented defaults. (#730)
- Stop counting a symlink to an in-tree regular file as a coverage limit. (#700)
- Compare host configuration in the Claude Code Stop hook when no manifest exists. (#661)
- Answer with one human stop when an untracked host baseline and a blocked host-capability expansion share a change. (#694)
- Compare past an unchanged partial or experimental surface instead of refusing every row (runtime contract 37, verifier schema
0.19). (#721) - Add 12 scripted route-parity cases for host-capability changes. (#662)
- Name the change first in the generated
AGENTS.mdandCLAUDE.mdblocks. (#662) - Read a Cursor rule's globs the way Cursor writes them. (#729)
- Read Claude Code
extraKnownMarketplaces, so a marketplace change produces a row. (#720) - Read a FastMCP tool's literal
readOnlyHintanddestructiveHintfrom source, as claims for the contradiction check to challenge. (#658) - Add the host-config precision harness under
benchmark/host-config/. (#659) - Make a URL-based MCP server's query part of its change digest. (#723)
- Resolve documented Claude skill and command frontmatter instead of refusing it. (#722)
- Add the cold-start harness under
benchmark/cold-start/. (#660) - Resolve local Claude Code settings layers by the documented precedence instead of refusing them. (#657)
- Publish a version that reviewed code declares advisory through the ordinary release pipeline, with no qualification claim. (#648)
- Run the FastMCP Context-injection SDK cross-checks on the SDK versions the
[mcp]extra allows. (#716) - Freeze the report contract at
1.0(report0.43→1.0, runtime contract 34). (#569) - Tell a widened permission rule from a narrowed one, and stop rating reading files as critical. (#657)
- Lead the Cursor instruction surface with
shipgate diff. (#662) - Read
.claude/hooks/hooks.json. (#689) - Keep a directory at a recognized host configuration path visible as a failed input. (#613)
- Materialize boundary paths from a verified tree in advisory
diffand manifest-free PR review. (#686) - Read the Cursor rule format Cursor actually writes, where
globs:has no value. (#712) - Name capability changes in manifest-free host PR review across
verify, PR comments andcheck. (#684) - Compare workflow permissions rather than whole-file edits in host diffs. (#685)
- Read literal TypeScript MCP tool descriptions from both SDK registration shapes. (#680)
- Detect shallow checkouts before
diffscans either side, and print a runnable recovery. (#683) - Read Go MCP tool descriptions from struct
Descriptionfields and direct description options. (#658) - Make every emitted next action lead somewhere, and prove it. (#650)
- Split the release into an advisory line and a qualified gate, and measure both. (#648)
- Compare against the detected base by default in
check. (#649) - Show six commands in
--help, and speak to a reader in their own language. (#652) - Add
shipgate diff: one row per host grant a change touches, with no manifest and no committed baseline. (#651) - Stop inventorying machine-written tool caches. (#598)
- Refuse a required tool source whose declared path is unavailable, once, for every reader. (#585)
- Read every counted hunk row, so header-shaped diff content stops being lost. (#611)
- Name what a change did to the bound each finding depends on. (#515)
- Bind reader-selected input directory names and no-follow entry kinds in the verification plan. (#630)
- Reconfirm recorded verification inputs before returning current control. (#627)
- Route host-only repositories from first discovery to the existing host audit, without a placeholder manifest. (#568)
- Compare supported instruction structure across verifier, local control, preflight, host drift and generated edit hooks. (#545)
- Count actual
insufficient_evidencequalification outcomes per profile, with denominators. (#520) - Label conservative action-effect projections separately from their static evidence. (#357)
- Retain base finding evidence for the fingerprint comparison, and expose what changed in its support. (#557)
- Show the bounded human review question at the start of existing PR comments and Check Run summaries. (#555)
- Evaluate externally signed decisions on the bounded human review request, without granting authority. (#537)
- Publish an unsigned, content-bound human review request for one documentation-quality class. (#536)
- Deprecate the path-only instruction-weakening check. (#516)
- Require review for test- and template-only agent names. (#533)
- Treat an
initgenerator failure as a product defect, not a request to refill a template. (#328) - Resolve FastMCP's injected
Contextin the signature projection, and say so when a type cannot be read. (#539) - Carry a changed MCP endpoint or credential reference to the reviewer. (#538)
- Read Python MCP server registration idioms. (#484)
- Add an adopters registry; its first published number is zero. (#475)
- Stop one unreadable application root from rejecting every agent name in the repository. (#398)
- Make the human entry path reach one useful review, and check it like every other distribution surface. (#498)
- Make the zero-install detector refuse an oversized candidate instead of reading it.
- Measure a reviewer's decision and the next eligible change in the design-partner pilot. (#521)
- Name only releases that exist in everything
initwrites. (#506) - Fix four lexer defects in the MCP registration reader, in both implementations. (#485)
- Read MCP registration sites in the zero-install detector. (#485)
- Register ten distribution surfaces and test that they agree with the engine. (#497)
- Stop grading any corpus case against
insufficient_evidence. (#520, #508) - Report one version from a preview wheel. (#491)
- Release on a cadence, and publish work that cannot be tagged through an unqualified preview. (#491)
Also in this release: the unpublished 0.16.0 line
Two milestones of engine work: the evidence-first declaration workflow, the
capability delta as a standalone attestation, a route for MCP servers whose
tool surface exists only as code, the compact agent-control envelope across
every setup command, and the release-integrity pipeline that binds a published
wheel to the commit it came from.
Highlights
- The capability delta is a standalone, independently verifiable
attestation.verifywrites an in-toto Statement whose subject is the
reviewed tree, andtools/verify-capability-delta.pyre-implements its 31
rules using nothing of ours. (#470, #469) - Declarations are evidence-first. The scanner asks only what it cannot
prove, pins every answer to the evidence behind it, and a declaration that
contradicts what was observed is no longer accepted in silence. (#409, #410) - MCP servers that ship no tool export now have a route. The official
MongoDB and Grafana servers were reported as not an agent project; the new
mcp_server_sourceinput reads the tool name at its registration site.
(#431) - One control envelope across the whole adoption walk.
init,detect,
doctor,preflightandverifyanswer "what may I do next?" with one
compact object instead of four artifacts and a guess. (#322, #323, #333,
#339) - A first adoption no longer blocks itself. The absent-input class, the
monorepo manifest routing, the scaffold disclosure and the launcher fixes
close the loop-breakers found in three adoption walks. (#334, #363, #384,
#387, #389, #441) - Human-facing output names subjects, not identities. Findings are grouped
by the thing they are about, every evidence gap labels its tool the way a
reader can use, and no surface prints a raw digest at a person. (#329, #364,
#403, #433) - The release pipeline proves what it publishes. Source-to-wheel byte
binding, separated verification and publication with a recoverable
transaction, a non-publishing rehearsal path, and a signed SBOM scoped to
the shipped wheel. (#342, #343, #344, #345, #355, #356) - A
0.xtag has an evidence bar it can meet, and it is a smaller corpus
rather than a weaker judgement: zero unsafe auto-passes, the κ floor and the
holdout fraction are unchanged. (#341)
Since 0.16.0b7
- The capability delta is now a standalone attestation any consumer can verify. (#470)
- An MCP server whose tool surface exists only as code now has a route. (#431)
- External PRs can now be evaluated without mutating tracked project files. (#326)
- Verifier and evidence explanations now preserve the fact that produced them. (#436, #396, #414, #420)
- The pre-1.0 qualification corpus now has a committed sourcing plan. (#456)
- The determinism boundary is now a published specification, generated from the code. (#473)
- One capability schema, frozen before either surface that will ship it. (#469)
- Replayable incident fixtures turn first-contact activation into a verifiable product path. (#471)
- Reviewed risk overrides no longer masquerade as scan observations. (#460)
- Capability delta now answers the reviewer’s question in subjects, without changing its machine contract. (#437, #439)
- Changed action declarations have a compact reviewer attestation. (#428)
- Cold-reader artifacts now lead with what the agent can do. (#463)
- The #424 repair loop is now pinned by a committed artifact. (#424)
- MCP clients can now see when a server's reassuring annotation contradicts the evidence beside it. (#462)
- The declaration questionnaire is now pinned by something committed. (#425)
- A reviewed risk tag is the manifest refining its own row, not source evidence contradicting it. (#424)
- A
0.xtag now has an evidence bar it can actually meet, and it is not a weaker judgement. (#341) - One control vocabulary reaches both streams, and the adoption walk composes end to end. (#323)
- The declaration continuation: a drafted proposal can now reach the person it was drafted for. (#429)
- The route is reachable on a first adoption, and states the only order the protocol allows. (#429)
- The declaration route is reachable on a first adoption. (#429)
initno longer writes a source type it guessed, and says when the block it wrote is a scaffold. (#441)- The same MCP server declared in two files is one capability, reconciled. (#403)
- The report's
Root agent:line names the agent instead of hashing it. (#329) - The loader-contract failure now offers a way forward.
- A new evidence gap now says which subject left the analysed surface. (#433)
- A published tool surface is one reviewed declaration, not one row per tool. (#432)
- A coding agent can now answer the declaration questions the scanner already knows the answers to. (#410, #409)
- Control packs: the rules layer, chosen once at
init. (#410, #413) - Human-facing findings are grouped by subject, and a recommendation names only what is missing. (#364)
- The questionnaire asks the unread questions first. (#1745, #419)
- A confirmed declaration is pinned to the evidence behind it.
environment.target: template, for a repository that ships to be copied.SHIP-TRUST-MANIFEST-UNPROTECTEDreads the file GitHub would read.SHIP-TRUST-MANIFEST-UNPROTECTED— who may change the gate.doctorsays which rung of the adoption ladder you are on.- A pin re-opens when authoritative evidence is replaced, not only when a reading appears. (#357)
- Existing
capabilities.lock.jsonfiles keep loading. - A merged declaration block reads in manifest field order.
- One action, one permission list, with no reviewed authority either.
- Authority follows credentials, not functions: declare it once per source. (#410)
- Ask only what the scanner cannot prove, and say how much is left. (#1745, #410, #357)
- Adopter-facing output stops naming the internal identity model. (#329, #327)
- A declaration cannot discharge a category it does not cover, and a published schema keeps its bytes. (#409, #411)
- A declaration weaker than the evidence inferred for it is no longer silent. (#409, #410, #357)
- Every evidence gap now labels a tool the way a reader can use, in every gap kind. (#403)
- Every stage that narrows the analysed surface now records what it removed, and the release decision can read it. (#403, #3076, #308)
verify --previewof a head that is not checked out now asks for the checkout, instead of stopping. (#397)detectnow publishes the same per-candidateinitcommandsinitdoes when a workspace holds several agent projects. (#397)- The first scan of an agent whose tools are imported symbols now scaffolds both layers it needs, instead of emitting nothing. (#361)
- Every
<REVIEW_REQUIRED>insuggested-declarations.yamlnow says what a legal answer is. (#388, #268) display_literalnow escapes Unicode noncharacters alongside the invisible code points it already covered. They are the same hazard — nothing reaches the reader, so two repository objects render identically — and two of them are worse: PyYAML rejects U+FFFE and U+FFFF outright, so an agent name carrying one made the generated declaration scaffold unparseable, because the document quoting that name in a comment could not be loaded at all. The encoding stays injective, soundisplay_literalstill recovers the name.verify --previewon a monorepo now names the project the pull request actually changed, instead of a repository root thatinitrefuses. (#394)detect's glob-based source suggestion re-ran the whole git inventory walk once per pattern — fifteen walks for one pass._candidate_files_matchingnow accepts an inventory the caller already built, which both fixes that and is what lets the preview evidence probe ask the same suggestion rule about a single directory rather than keeping a second copy of it.- Project discovery no longer presents a truncated candidate list as a complete one. (#395)
- Google ADK extraction confidence is now measured on the module, not hardcoded. (#393)
- A tool inventory now completes the source that asked for it, instead of shadowing it. (#386)
- An input that is not there is no longer reported as an input with the wrong shape, and no command creates the workspace it was asked to inspect. (#389, #384)
- A manifest type mismatch is an edit, not a bug report. (#387)
- A Google ADK sub-agent's tools are part of the analyzed surface, and a tool the gate did not look at can no longer go unmentioned. (#385)
- One command runs Agents Shipgate from this checkout, and
doctornow says which Shipgate answered. (#334, #338, #322) - The launcher announces a spelling the operating system will actually start.
- Two virtual environments over one base are no longer one interpreter.
PATHlookup follows the shell's rule, not "a file exists there".- A trampoline target must be a command, not a mention of one.
- A quoted program token is read before it is judged to be ours.
- A
#!/bin/shconsole-script wrapper reports the interpreter itexecs. - An
insufficient_evidenceverdict now leads with the gap you can close, and the three lines that announce it agree. (#362) - Verifier schema
0.8 → 0.9. - The PR comment reports the proven fact, not the routing flag.
- The policy comparator honors the split check-id aliases.
- Accepted debt survives the split.
- The headline is bounded once, at the end.
- Unicode format controls are stripped from headline material.
- The verifier headline leads with the release blockers, not with the governance notice that outranked them. (#1917, #365)
- A first adoption no longer reports a policy weakening that could not have happened.
- The blocker title quoted into the headline is normalized and bounded.
initranks agent-name candidates instead of taking the first one it trips over. (#320, #1745, #324)- First adoption inside a monorepo no longer starts by writing the wrong manifest. (#1, #363)
- One control vocabulary across the adoption walk.
- A manifest declaration a person owes is no longer routed to the agent. (#323)
- The
AgentControlunion is unchanged, and the compatibility floor stays at21. - A completion cannot rest on a negative verdict.
- A manifest that is not UTF-8 is refused, not rewritten.
- The envelope only calls a string a command when something can run it.
control.next_action.pathnames the file byte for byte.- Every
doctor --jsonpayload carries the route, including the earliest failure. - A dry run that wrote the CI workflow no longer says nothing was written.
scanis outside this rollout, and now says so. (#323)- The recommended next command now runs where it was recommended. (#322)
- A prompt or policy edit outside the repository root — or spelled
Policies/— no longer reports as "nothing in this PR signals a tool-surface change.". - The
on-tool-source-changesCI recipes are retired. - One compact object now answers "what may I do next?", instead of four artifacts and a guess. (#333, #323, #338)
- The release pipeline now proves the wheel it publishes came from the tagged commit.
- Verification and publication are now separate jobs, and a partial publish is recoverable.
- The qualification signer identity is reviewed code, and a release candidate must have been rehearsed.
- The signed SBOM now describes the shipped wheel instead of the CI machine.
- A release candidate can be rehearsed without any publication authority.
- Release test selection matches CI, so candidates fail on correctness evidence rather than timing noise.
- The release page carries the changelog, and the release runs the environment CI approved. (#345)
- Insufficient-evidence remediation now stays framework-aware from the decision engine through every primary short-form surface. (#318)
- Human review now blocks merge and completion, not publication of the evidence a human needs in order to review. (#335)
- Local verification now evaluates committed and uncommitted edits as one effective worktree diff. (#336)
- A coding agent can no longer enforce a verifier result the workspace has outgrown. (#339)
- An unreadable PR diff is no longer reported as "nothing here is agent-related.".
- Google ADK repositories that share one tool between agents can be scanned again.
- Standalone scans now retire the complete verifier route as one lifecycle set.
- The trigger catalog now recognizes a Google ADK
tools=[...]list, and stops calling a bare package token a version bump. input_set_idnow covers every input the adapters actually read. (#299)SHIP-VERIFY-POLICY-WEAKENEDcan now actually see a weakened CI gate.initno longer fails on a repository that names two files the same.- A protected-surface stop now names the route, and the non-route that looks like one.
- A first adoption no longer reads as a policy weakening.
- The manifest a run actually loaded is a trust root.
checkdetects which agent is running it.check,audit, andpreflighthonor the agent-mode error contract.- A rerun command that actually reruns.
- Preflight recovery keeps the request it failed on.
- Detached diffs never authorize checkout-dependent verification.
- A failed baseline is never recovered by overwriting it.
- Host-audit filesystem failures follow the catalog.
- The audit id distinguishes the actor.
- Static control inputs now fail closed on identity and resource ambiguity.
- Portable host instructions are protected consistently.
- Mechanical repair authorization is subject-bound.
- Adoption wording stands down when something was genuinely weakened.
- A way out of
insufficient_evidence(#292). (#292) - Unfilled scaffold placeholders are rejected by the manifest.
- The authority template was unfillable.
- Evidence gaps say whether this diff caused them.
- Framework-correct low-confidence remedy.
0.16.0b7
- Graded local boundary stop (UX P0, contract v19).
- Stop hook follows
control.state. - Own-repo CI verify gates on
blocked,unknownagain. (#274) - Version advances.
0.16.0b6
- Reproducible verification identity (P0).
- Terminal receipts and portable execution boundary.
- Externally rooted exact-operation authorization (contract v18).
- Identity and authorization contract versions.
- Immutable CI subject.
- Non-forgeable trust decay.
- Agent-authored coverage proposals (contract v18 clarification).
- Codex marketplace coverage and plugin-path containment.
0.16.0b5
- Evidence-basis policy gate (P0).
- Non-waivable policy applicability gaps.
- Evidence contract versions.
0.16.0b4
- Complete zero-config multi-host boundary.
- Host-neutral boundary contract.
- Evidence-bearing host inventory.
- Boundary beta hardening.
- Correction to the original host-governance claim.
0.16.0b3
- Unambiguous agent control contract (P0).
- Control contract versions.
- Execution, applicability, and mergeability are separate.
- Conductor OSS workflow JSON adapter.
0.16.0b2
- Root-reachable agent binding graph (P0).
- Binding contract versions.
- Provider-scoped canonical tool identity (P0).
- Identity-safe policies, diffs, traces, and debt.
- Identity contract versions.
0.16.0b1
- Evidence-backed
passedverdict. - Normalized semantic evidence contract.
- Machine-readable static-verdict boundary.
- Capability standard v0.2.
- Qualification trust boundary is explicit.