Skip to content

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 22:31
· 65 commits to main since this release
Immutable release. Only release title and notes can be modified.
bace7c1

The first published release since 0.15.0, on the advisory channel. It
publishes diff, check, audit --host, drift and advisory PR comments, and
makes no qualification claim. 0.16.0 was prepared but never published, so
everything in its section below ships here too.

The full reviewed prose is in
docs/changelog/1.0.0.md, and for the 0.16.0
line in docs/changelog/0.16.0.md.
This section
is the release note; those files are the record.

Migration notes: read every Migration Note: 1.0.0 and
Migration Note: 0.16.0b* entry in STABILITY.md before
upgrading from 0.15.0. Several change a published schema or a contract
version.

Highlights

  • shipgate diff names what a change does to an agent's authority: one row
    per host grant, with no manifest and no committed baseline. (#651)
  • Host comparisons reach real repositories. In-tree links, documented
    frontmatter, JSON with comments, Cursor globs, plugin marketplaces and
    unchanged partial surfaces no longer refuse the comparison. (#700, #720,
    #721, #722, #723, #729, #730, #731)
  • A narrowing is not an expansion. Tightening a rule no longer reads as a
    widened allowlist, and a settings narrowing finishes without a human review.
    (#657, #661)
  • The Claude Code hooks stay fast and quiet. The Stop hook compares host
    configuration in under a second and repeats no advisory within a session.
    (#661)
  • The control envelope names the change in a bounded capability_rows
    block, and the generated agent instructions lead with it. (#662)
  • Measured on the 1.0.0 candidate wheel, including where it falls short.
    On the wheel Release Engine Smoke exercised on 747d6080 (1b846258…): ten pinned public
    MCP servers gave 76 findings, 1 false (1.3%, bar under 2%); a fresh clone
    reached a correct comparison in 26 of 30 public repositories (bar 24); on 50
    public host-config PRs, row precision is 70 of 70, while widening recall
    (55 of 65) and the benign zero-row rate (5 of 6) stay below their bars, with
    every miss named in its run. (#658, #660, #659)
  • The report contract is frozen at 1.0. (#569)
  • An advisory version publishes through the ordinary release pipeline,
    declared in .github/release-channels.json. (#648)

Changes

  • Re-run the three live measurements on the wheel Release Engine Smoke exercised on 747d6080, after the last engine changes, as the runs of record; every outcome is unchanged. (#658, #659, #660)
  • Build the optional MCP server on the SDK 2.x MCPServer, the API the [mcp] extra has installed since SDK 2.0, so mcp-serve starts again. An SDK without it is named as a version problem, and CI installs the extra at its floor and its newest release. (#713)
  • Read Git pathnames that contain spaces in check, verify and the MCP check tool. A change touching docs/new scope/notes.md no longer asks for review of an invalid path, and no longer crashes check when a manifest is configured. (#581)
  • Name step action references, named reusable-workflow secrets and remote MCP URL paths as unread host surfaces, say that a hook row does not prove the host loads the file, and state which symlinks refuse a comparison. (#693, #714, #771, #772)
  • Preserve host permission-change semantics when check redacts rule arguments; scoped narrowing and widening now agree with diff and verify. (#767)
  • Report incomplete coverage for malformed Claude permission containers and allow/deny/ask arrays instead of a covered no-change comparison. Unknown extension settings remain allowed. (#768)
  • Exercise the #659 oracle with positive, narrowing and neutral controls a bad engine fails, and record how its expectations are labelled. (#659)
  • Give release verification's correctness suite a budget re-derived for today's suite, which had outgrown its 20 minutes. (#648)
  • Re-run the three live measurements on the 1.0.0 candidate wheel as the runs of record, and refuse a committed run with an unmasked local path. (#658, #659, #660)
  • Name composite actions and hook-run scripts as unread host surfaces on the support page. (#701, #702)
  • Remove the runbook's manual undraft, which skipped every finalisation check; re-running finalize is the only recovery. (#618)
  • Make the release rehearsal's provenance drill reach the payload it tampers with, after an untouched control copy passes. (#615)
  • Name every kind of host expansion in preflight's explanation, with the total and what was folded. (#681)
  • Publish as 1.0.0 on the advisory channel, state the 1.x stability line, and keep codex-boundary-json and legacy policy discovery through 1.x.
  • Commit the ten-server MCP findings table: 76 findings, 1 false (1.3%), re-scored in CI against committed labels. (#658)
  • Leave eval-harness and mock tools out of an MCP server's source catalog. (#658)
  • Stop reading a topic as a contradiction of readOnlyHint: only a modifying effect contradicts it, and a keyword inference also needs an action verb. (#658)
  • Stop reporting an MCP source description the reader cannot resolve as missing. (#658)
  • Read .vscode/mcp.json as JSON with comments. (#659)
  • Answer the Claude Code Stop hook's host comparison in under a second. (#661)
  • Stop repeating hook advisories within a Claude Code session. (#661)
  • Let a host settings narrowing finish without a human review. (#661)
  • Document that check and verify publish changed-file paths verbatim. (#742)
  • Read through an in-tree link at a boundary path (runtime contract 39, host-grants inventory 0.5). (#700)
  • Read Go MCP servers' literal tool hints for the contradiction check. (#658)
  • Stop calling a narrowed allow rule an expanded allowlist in check and verify. (#661)
  • Keep credential-shaped bytes in a directory or file name out of host inventory output. (#590)
  • Name the host capability change in the compact control envelope (runtime contract 38). (#662)
  • Support .vscode/mcp.json as a first-class host surface. (#731)
  • Digest undocumented skill and command frontmatter keys, and read a skill without frontmatter by its documented defaults. (#730)
  • Stop counting a symlink to an in-tree regular file as a coverage limit. (#700)
  • Compare host configuration in the Claude Code Stop hook when no manifest exists. (#661)
  • Answer with one human stop when an untracked host baseline and a blocked host-capability expansion share a change. (#694)
  • Compare past an unchanged partial or experimental surface instead of refusing every row (runtime contract 37, verifier schema 0.19). (#721)
  • Add 12 scripted route-parity cases for host-capability changes. (#662)
  • Name the change first in the generated AGENTS.md and CLAUDE.md blocks. (#662)
  • Read a Cursor rule's globs the way Cursor writes them. (#729)
  • Read Claude Code extraKnownMarketplaces, so a marketplace change produces a row. (#720)
  • Read a FastMCP tool's literal readOnlyHint and destructiveHint from source, as claims for the contradiction check to challenge. (#658)
  • Add the host-config precision harness under benchmark/host-config/. (#659)
  • Make a URL-based MCP server's query part of its change digest. (#723)
  • Resolve documented Claude skill and command frontmatter instead of refusing it. (#722)
  • Add the cold-start harness under benchmark/cold-start/. (#660)
  • Resolve local Claude Code settings layers by the documented precedence instead of refusing them. (#657)
  • Publish a version that reviewed code declares advisory through the ordinary release pipeline, with no qualification claim. (#648)
  • Run the FastMCP Context-injection SDK cross-checks on the SDK versions the [mcp] extra allows. (#716)
  • Freeze the report contract at 1.0 (report 0.43 → 1.0, runtime contract 34). (#569)
  • Tell a widened permission rule from a narrowed one, and stop rating reading files as critical. (#657)
  • Lead the Cursor instruction surface with shipgate diff. (#662)
  • Read .claude/hooks/hooks.json. (#689)
  • Keep a directory at a recognized host configuration path visible as a failed input. (#613)
  • Materialize boundary paths from a verified tree in advisory diff and manifest-free PR review. (#686)
  • Read the Cursor rule format Cursor actually writes, where globs: has no value. (#712)
  • Name capability changes in manifest-free host PR review across verify, PR comments and check. (#684)
  • Compare workflow permissions rather than whole-file edits in host diffs. (#685)
  • Read literal TypeScript MCP tool descriptions from both SDK registration shapes. (#680)
  • Detect shallow checkouts before diff scans either side, and print a runnable recovery. (#683)
  • Read Go MCP tool descriptions from struct Description fields and direct description options. (#658)
  • Make every emitted next action lead somewhere, and prove it. (#650)
  • Split the release into an advisory line and a qualified gate, and measure both. (#648)
  • Compare against the detected base by default in check. (#649)
  • Show six commands in --help, and speak to a reader in their own language. (#652)
  • Add shipgate diff: one row per host grant a change touches, with no manifest and no committed baseline. (#651)
  • Stop inventorying machine-written tool caches. (#598)
  • Refuse a required tool source whose declared path is unavailable, once, for every reader. (#585)
  • Read every counted hunk row, so header-shaped diff content stops being lost. (#611)
  • Name what a change did to the bound each finding depends on. (#515)
  • Bind reader-selected input directory names and no-follow entry kinds in the verification plan. (#630)
  • Reconfirm recorded verification inputs before returning current control. (#627)
  • Route host-only repositories from first discovery to the existing host audit, without a placeholder manifest. (#568)
  • Compare supported instruction structure across verifier, local control, preflight, host drift and generated edit hooks. (#545)
  • Count actual insufficient_evidence qualification outcomes per profile, with denominators. (#520)
  • Label conservative action-effect projections separately from their static evidence. (#357)
  • Retain base finding evidence for the fingerprint comparison, and expose what changed in its support. (#557)
  • Show the bounded human review question at the start of existing PR comments and Check Run summaries. (#555)
  • Evaluate externally signed decisions on the bounded human review request, without granting authority. (#537)
  • Publish an unsigned, content-bound human review request for one documentation-quality class. (#536)
  • Deprecate the path-only instruction-weakening check. (#516)
  • Require review for test- and template-only agent names. (#533)
  • Treat an init generator failure as a product defect, not a request to refill a template. (#328)
  • Resolve FastMCP's injected Context in the signature projection, and say so when a type cannot be read. (#539)
  • Carry a changed MCP endpoint or credential reference to the reviewer. (#538)
  • Read Python MCP server registration idioms. (#484)
  • Add an adopters registry; its first published number is zero. (#475)
  • Stop one unreadable application root from rejecting every agent name in the repository. (#398)
  • Make the human entry path reach one useful review, and check it like every other distribution surface. (#498)
  • Make the zero-install detector refuse an oversized candidate instead of reading it.
  • Measure a reviewer's decision and the next eligible change in the design-partner pilot. (#521)
  • Name only releases that exist in everything init writes. (#506)
  • Fix four lexer defects in the MCP registration reader, in both implementations. (#485)
  • Read MCP registration sites in the zero-install detector. (#485)
  • Register ten distribution surfaces and test that they agree with the engine. (#497)
  • Stop grading any corpus case against insufficient_evidence. (#520, #508)
  • Report one version from a preview wheel. (#491)
  • Release on a cadence, and publish work that cannot be tagged through an unqualified preview. (#491)

Also in this release: the unpublished 0.16.0 line

Two milestones of engine work: the evidence-first declaration workflow, the
capability delta as a standalone attestation, a route for MCP servers whose
tool surface exists only as code, the compact agent-control envelope across
every setup command, and the release-integrity pipeline that binds a published
wheel to the commit it came from.

Highlights

  • The capability delta is a standalone, independently verifiable
    attestation.
    verify writes an in-toto Statement whose subject is the
    reviewed tree, and tools/verify-capability-delta.py re-implements its 31
    rules using nothing of ours. (#470, #469)
  • Declarations are evidence-first. The scanner asks only what it cannot
    prove, pins every answer to the evidence behind it, and a declaration that
    contradicts what was observed is no longer accepted in silence. (#409, #410)
  • MCP servers that ship no tool export now have a route. The official
    MongoDB and Grafana servers were reported as not an agent project; the new
    mcp_server_source input reads the tool name at its registration site.
    (#431)
  • One control envelope across the whole adoption walk. init, detect,
    doctor, preflight and verify answer "what may I do next?" with one
    compact object instead of four artifacts and a guess. (#322, #323, #333,
    #339)
  • A first adoption no longer blocks itself. The absent-input class, the
    monorepo manifest routing, the scaffold disclosure and the launcher fixes
    close the loop-breakers found in three adoption walks. (#334, #363, #384,
    #387, #389, #441)
  • Human-facing output names subjects, not identities. Findings are grouped
    by the thing they are about, every evidence gap labels its tool the way a
    reader can use, and no surface prints a raw digest at a person. (#329, #364,
    #403, #433)
  • The release pipeline proves what it publishes. Source-to-wheel byte
    binding, separated verification and publication with a recoverable
    transaction, a non-publishing rehearsal path, and a signed SBOM scoped to
    the shipped wheel. (#342, #343, #344, #345, #355, #356)
  • A 0.x tag has an evidence bar it can meet, and it is a smaller corpus
    rather than a weaker judgement: zero unsafe auto-passes, the κ floor and the
    holdout fraction are unchanged. (#341)

Since 0.16.0b7

  • The capability delta is now a standalone attestation any consumer can verify. (#470)
  • An MCP server whose tool surface exists only as code now has a route. (#431)
  • External PRs can now be evaluated without mutating tracked project files. (#326)
  • Verifier and evidence explanations now preserve the fact that produced them. (#436, #396, #414, #420)
  • The pre-1.0 qualification corpus now has a committed sourcing plan. (#456)
  • The determinism boundary is now a published specification, generated from the code. (#473)
  • One capability schema, frozen before either surface that will ship it. (#469)
  • Replayable incident fixtures turn first-contact activation into a verifiable product path. (#471)
  • Reviewed risk overrides no longer masquerade as scan observations. (#460)
  • Capability delta now answers the reviewer’s question in subjects, without changing its machine contract. (#437, #439)
  • Changed action declarations have a compact reviewer attestation. (#428)
  • Cold-reader artifacts now lead with what the agent can do. (#463)
  • The #424 repair loop is now pinned by a committed artifact. (#424)
  • MCP clients can now see when a server's reassuring annotation contradicts the evidence beside it. (#462)
  • The declaration questionnaire is now pinned by something committed. (#425)
  • A reviewed risk tag is the manifest refining its own row, not source evidence contradicting it. (#424)
  • A 0.x tag now has an evidence bar it can actually meet, and it is not a weaker judgement. (#341)
  • One control vocabulary reaches both streams, and the adoption walk composes end to end. (#323)
  • The declaration continuation: a drafted proposal can now reach the person it was drafted for. (#429)
  • The route is reachable on a first adoption, and states the only order the protocol allows. (#429)
  • The declaration route is reachable on a first adoption. (#429)
  • init no longer writes a source type it guessed, and says when the block it wrote is a scaffold. (#441)
  • The same MCP server declared in two files is one capability, reconciled. (#403)
  • The report's Root agent: line names the agent instead of hashing it. (#329)
  • The loader-contract failure now offers a way forward.
  • A new evidence gap now says which subject left the analysed surface. (#433)
  • A published tool surface is one reviewed declaration, not one row per tool. (#432)
  • A coding agent can now answer the declaration questions the scanner already knows the answers to. (#410, #409)
  • Control packs: the rules layer, chosen once at init. (#410, #413)
  • Human-facing findings are grouped by subject, and a recommendation names only what is missing. (#364)
  • The questionnaire asks the unread questions first. (#1745, #419)
  • A confirmed declaration is pinned to the evidence behind it.
  • environment.target: template, for a repository that ships to be copied.
  • SHIP-TRUST-MANIFEST-UNPROTECTED reads the file GitHub would read.
  • SHIP-TRUST-MANIFEST-UNPROTECTED — who may change the gate.
  • doctor says which rung of the adoption ladder you are on.
  • A pin re-opens when authoritative evidence is replaced, not only when a reading appears. (#357)
  • Existing capabilities.lock.json files keep loading.
  • A merged declaration block reads in manifest field order.
  • One action, one permission list, with no reviewed authority either.
  • Authority follows credentials, not functions: declare it once per source. (#410)
  • Ask only what the scanner cannot prove, and say how much is left. (#1745, #410, #357)
  • Adopter-facing output stops naming the internal identity model. (#329, #327)
  • A declaration cannot discharge a category it does not cover, and a published schema keeps its bytes. (#409, #411)
  • A declaration weaker than the evidence inferred for it is no longer silent. (#409, #410, #357)
  • Every evidence gap now labels a tool the way a reader can use, in every gap kind. (#403)
  • Every stage that narrows the analysed surface now records what it removed, and the release decision can read it. (#403, #3076, #308)
  • verify --preview of a head that is not checked out now asks for the checkout, instead of stopping. (#397)
  • detect now publishes the same per-candidate init commands init does when a workspace holds several agent projects. (#397)
  • The first scan of an agent whose tools are imported symbols now scaffolds both layers it needs, instead of emitting nothing. (#361)
  • Every <REVIEW_REQUIRED> in suggested-declarations.yaml now says what a legal answer is. (#388, #268)
  • display_literal now escapes Unicode noncharacters alongside the invisible code points it already covered. They are the same hazard — nothing reaches the reader, so two repository objects render identically — and two of them are worse: PyYAML rejects U+FFFE and U+FFFF outright, so an agent name carrying one made the generated declaration scaffold unparseable, because the document quoting that name in a comment could not be loaded at all. The encoding stays injective, so undisplay_literal still recovers the name.
  • verify --preview on a monorepo now names the project the pull request actually changed, instead of a repository root that init refuses. (#394)
  • detect's glob-based source suggestion re-ran the whole git inventory walk once per pattern — fifteen walks for one pass. _candidate_files_matching now accepts an inventory the caller already built, which both fixes that and is what lets the preview evidence probe ask the same suggestion rule about a single directory rather than keeping a second copy of it.
  • Project discovery no longer presents a truncated candidate list as a complete one. (#395)
  • Google ADK extraction confidence is now measured on the module, not hardcoded. (#393)
  • A tool inventory now completes the source that asked for it, instead of shadowing it. (#386)
  • An input that is not there is no longer reported as an input with the wrong shape, and no command creates the workspace it was asked to inspect. (#389, #384)
  • A manifest type mismatch is an edit, not a bug report. (#387)
  • A Google ADK sub-agent's tools are part of the analyzed surface, and a tool the gate did not look at can no longer go unmentioned. (#385)
  • One command runs Agents Shipgate from this checkout, and doctor now says which Shipgate answered. (#334, #338, #322)
  • The launcher announces a spelling the operating system will actually start.
  • Two virtual environments over one base are no longer one interpreter.
  • PATH lookup follows the shell's rule, not "a file exists there".
  • A trampoline target must be a command, not a mention of one.
  • A quoted program token is read before it is judged to be ours.
  • A #!/bin/sh console-script wrapper reports the interpreter it execs.
  • An insufficient_evidence verdict now leads with the gap you can close, and the three lines that announce it agree. (#362)
  • Verifier schema 0.8 → 0.9.
  • The PR comment reports the proven fact, not the routing flag.
  • The policy comparator honors the split check-id aliases.
  • Accepted debt survives the split.
  • The headline is bounded once, at the end.
  • Unicode format controls are stripped from headline material.
  • The verifier headline leads with the release blockers, not with the governance notice that outranked them. (#1917, #365)
  • A first adoption no longer reports a policy weakening that could not have happened.
  • The blocker title quoted into the headline is normalized and bounded.
  • init ranks agent-name candidates instead of taking the first one it trips over. (#320, #1745, #324)
  • First adoption inside a monorepo no longer starts by writing the wrong manifest. (#1, #363)
  • One control vocabulary across the adoption walk.
  • A manifest declaration a person owes is no longer routed to the agent. (#323)
  • The AgentControl union is unchanged, and the compatibility floor stays at 21.
  • A completion cannot rest on a negative verdict.
  • A manifest that is not UTF-8 is refused, not rewritten.
  • The envelope only calls a string a command when something can run it.
  • control.next_action.path names the file byte for byte.
  • Every doctor --json payload carries the route, including the earliest failure.
  • A dry run that wrote the CI workflow no longer says nothing was written.
  • scan is outside this rollout, and now says so. (#323)
  • The recommended next command now runs where it was recommended. (#322)
  • A prompt or policy edit outside the repository root — or spelled Policies/ — no longer reports as "nothing in this PR signals a tool-surface change.".
  • The on-tool-source-changes CI recipes are retired.
  • One compact object now answers "what may I do next?", instead of four artifacts and a guess. (#333, #323, #338)
  • The release pipeline now proves the wheel it publishes came from the tagged commit.
  • Verification and publication are now separate jobs, and a partial publish is recoverable.
  • The qualification signer identity is reviewed code, and a release candidate must have been rehearsed.
  • The signed SBOM now describes the shipped wheel instead of the CI machine.
  • A release candidate can be rehearsed without any publication authority.
  • Release test selection matches CI, so candidates fail on correctness evidence rather than timing noise.
  • The release page carries the changelog, and the release runs the environment CI approved. (#345)
  • Insufficient-evidence remediation now stays framework-aware from the decision engine through every primary short-form surface. (#318)
  • Human review now blocks merge and completion, not publication of the evidence a human needs in order to review. (#335)
  • Local verification now evaluates committed and uncommitted edits as one effective worktree diff. (#336)
  • A coding agent can no longer enforce a verifier result the workspace has outgrown. (#339)
  • An unreadable PR diff is no longer reported as "nothing here is agent-related.".
  • Google ADK repositories that share one tool between agents can be scanned again.
  • Standalone scans now retire the complete verifier route as one lifecycle set.
  • The trigger catalog now recognizes a Google ADK tools=[...] list, and stops calling a bare package token a version bump.
  • input_set_id now covers every input the adapters actually read. (#299)
  • SHIP-VERIFY-POLICY-WEAKENED can now actually see a weakened CI gate.
  • init no longer fails on a repository that names two files the same.
  • A protected-surface stop now names the route, and the non-route that looks like one.
  • A first adoption no longer reads as a policy weakening.
  • The manifest a run actually loaded is a trust root.
  • check detects which agent is running it.
  • check, audit, and preflight honor the agent-mode error contract.
  • A rerun command that actually reruns.
  • Preflight recovery keeps the request it failed on.
  • Detached diffs never authorize checkout-dependent verification.
  • A failed baseline is never recovered by overwriting it.
  • Host-audit filesystem failures follow the catalog.
  • The audit id distinguishes the actor.
  • Static control inputs now fail closed on identity and resource ambiguity.
  • Portable host instructions are protected consistently.
  • Mechanical repair authorization is subject-bound.
  • Adoption wording stands down when something was genuinely weakened.
  • A way out of insufficient_evidence (#292). (#292)
  • Unfilled scaffold placeholders are rejected by the manifest.
  • The authority template was unfillable.
  • Evidence gaps say whether this diff caused them.
  • Framework-correct low-confidence remedy.

0.16.0b7

  • Graded local boundary stop (UX P0, contract v19).
  • Stop hook follows control.state.
  • Own-repo CI verify gates on blocked,unknown again. (#274)
  • Version advances.

0.16.0b6

  • Reproducible verification identity (P0).
  • Terminal receipts and portable execution boundary.
  • Externally rooted exact-operation authorization (contract v18).
  • Identity and authorization contract versions.
  • Immutable CI subject.
  • Non-forgeable trust decay.
  • Agent-authored coverage proposals (contract v18 clarification).
  • Codex marketplace coverage and plugin-path containment.

0.16.0b5

  • Evidence-basis policy gate (P0).
  • Non-waivable policy applicability gaps.
  • Evidence contract versions.

0.16.0b4

  • Complete zero-config multi-host boundary.
  • Host-neutral boundary contract.
  • Evidence-bearing host inventory.
  • Boundary beta hardening.
  • Correction to the original host-governance claim.

0.16.0b3

  • Unambiguous agent control contract (P0).
  • Control contract versions.
  • Execution, applicability, and mergeability are separate.
  • Conductor OSS workflow JSON adapter.

0.16.0b2

  • Root-reachable agent binding graph (P0).
  • Binding contract versions.
  • Provider-scoped canonical tool identity (P0).
  • Identity-safe policies, diffs, traces, and debt.
  • Identity contract versions.

0.16.0b1

  • Evidence-backed passed verdict.
  • Normalized semantic evidence contract.
  • Machine-readable static-verdict boundary.
  • Capability standard v0.2.
  • Qualification trust boundary is explicit.