Skip to content

Releases: agentrust-io/integrations

agentrust-capture-core 0.1.1

Choose a tag to compare

@imran-siddique imran-siddique released this 23 Aug 20:49
9839486

What's Changed

  • Verify trace adapter release provenance by @imran-siddique in #114
  • build(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in #110
  • build(deps): update agentrust-trace requirement from >=0.5.1 to >=0.9.0 by @dependabot[bot] in #104
  • build(deps): bump agentrust-trace from 0.5.1 to 0.9.0 in /integrations/ramen-ai-cmcp by @dependabot[bot] in #108
  • build(deps): update agentrust-trace-tests requirement from <0.5,>=0.4.1 to >=0.5.0,<0.6 by @dependabot[bot] in #105
  • build(deps): update agentrust-trace-tests requirement from <0.5,>=0.4 to >=0.4,<0.6 in /integrations/comply54 by @dependabot[bot] in #106
  • build(deps): update agent-manifest requirement from >=0.10.0 to >=0.11.0 by @dependabot[bot] in #107
  • build(deps-dev): bump agentrust-trace-tests from 0.4.1 to 0.5.0 in /integrations/ramen-ai-cmcp by @dependabot[bot] in #109
  • build(deps): bump lycheeverse/lychee-action from 2.6.1 to 2.9.0 by @dependabot[bot] in #111
  • docs: record capture core dependency break by @imran-siddique in #115
  • fix(copilot): measure documented MCP surfaces by @imran-siddique in #116
  • ci: gate Copilot composition drift by @imran-siddique in #119
  • fix(copilot): measure the three other documented MCP surfaces by @imran-siddique in #117
  • fix(copilot): re-approve the baseline for measurement scope 2 by @imran-siddique in #120
  • fix: enforce all repository maintainers by @imran-siddique in #123
  • feat: add agent surfaces for Cursor, Windsurf, Gemini CLI by @kingztech2019 in #121
  • build(deps-dev): bump hatchling from 1.27.0 to 1.32.0 in /packages/agentrust-trace-adapters by @dependabot[bot] in #122
  • fix(langchain): exercise the callback adapter through LangGraph (#96) by @noah-ing in #124
  • feat: generate marketplace catalog from manifests by @imran-siddique in #125
  • feat: automate AGT marketplace snapshot by @imran-siddique in #126
  • docs: document project sponsorship roles by @imran-siddique in #127
  • docs: update project contact email by @imran-siddique in #129
  • ci: fail closed when CodeQL analysis fails by @imran-siddique in #130

New Contributors

Full Changelog: trace-adapters-v0.1.0...capture-core-v0.1.1

What's Changed

  • Verify trace adapter release provenance by @imran-siddique in #114
  • build(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in #110
  • build(deps): update agentrust-trace requirement from >=0.5.1 to >=0.9.0 by @dependabot[bot] in #104
  • build(deps): bump agentrust-trace from 0.5.1 to 0.9.0 in /integrations/ramen-ai-cmcp by @dependabot[bot] in #108
  • build(deps): update agentrust-trace-tests requirement from <0.5,>=0.4.1 to >=0.5.0,<0.6 by @dependabot[bot] in #105
  • build(deps): update agentrust-trace-tests requirement from <0.5,>=0.4 to >=0.4,<0.6 in /integrations/comply54 by @dependabot[bot] in #106
  • build(deps): update agent-manifest requirement from >=0.10.0 to >=0.11.0 by @dependabot[bot] in #107
  • build(deps-dev): bump agentrust-trace-tests from 0.4.1 to 0.5.0 in /integrations/ramen-ai-cmcp by @dependabot[bot] in #109
  • build(deps): bump lycheeverse/lychee-action from 2.6.1 to 2.9.0 by @dependabot[bot] in #111
  • docs: record capture core dependency break by @imran-siddique in #115
  • fix(copilot): measure documented MCP surfaces by @imran-siddique in #116
  • ci: gate Copilot composition drift by @imran-siddique in #119
  • fix(copilot): measure the three other documented MCP surfaces by @imran-siddique in #117
  • fix(copilot): re-approve the baseline for measurement scope 2 by @imran-siddique in #120
  • fix: enforce all repository maintainers by @imran-siddique in #123
  • feat: add agent surfaces for Cursor, Windsurf, Gemini CLI by @kingztech2019 in #121
  • build(deps-dev): bump hatchling from 1.27.0 to 1.32.0 in /packages/agentrust-trace-adapters by @dependabot[bot] in #122
  • fix(langchain): exercise the callback adapter through LangGraph (#96) by @noah-ing in #124
  • feat: generate marketplace catalog from manifests by @imran-siddique in #125
  • feat: automate AGT marketplace snapshot by @imran-siddique in #126
  • docs: document project sponsorship roles by @imran-siddique in #127
  • docs: update project contact email by @imran-siddique in #129
  • ci: fail closed when CodeQL analysis fails by @imran-siddique in #130

New Contributors

Full Changelog: trace-adapters-v0.1.0...capture-core-v0.1.1

trace-adapters-v0.1.0

Choose a tag to compare

@github-actions github-actions released this 14 Aug 04:36
2f8e921

What's Changed

  • refactor: depend on the published core, drop the vendored copies by @imran-siddique in #72
  • chore(ci): pin agentrust-io/.github checkout to an immutable SHA by @imran-siddique in #79
  • build(deps): bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 by @dependabot[bot] in #80
  • build(deps): update agentrust-trace requirement from >=0.5 to >=0.5.1 by @dependabot[bot] in #81
  • fix(ramen-ai-cmcp): emit the TRACE v0.2 profile by @imran-siddique in #85
  • build(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in #82
  • build(deps): bump actions/setup-python from 5.6.0 to 7.0.0 by @dependabot[bot] in #83
  • build(deps): bump actions/checkout from 4.3.1 to 7.0.1 by @dependabot[bot] in #84
  • integrations/aeoess-aps: add APS PolicyDecision to TRACE Level 0 mapping by @aeoess in #86
  • feat(comply54): add conformance CI to reach Verified tier by @kingztech2019 in #87
  • feat(adapters): a library for records built from someone else's evidence by @imran-siddique in #89
  • feat(otel-genai): build Trust Records from OpenTelemetry GenAI spans by @imran-siddique in #90
  • feat(ramen-ai-cmcp): upgrade to native trace v0.2 signing to satisfy … by @ramen-noodle6 in #88
  • feat(langchain): a Trust Record from a LangChain run, without the payloads by @imran-siddique in #91
  • feat(llamaindex): the second framework adapter, with a stricter reading rule by @imran-siddique in #92
  • feat(adapters): default enforcement_mode to declared now that it exists by @imran-siddique in #93
  • build(deps): update agent-manifest requirement from >=0.7.0 to >=0.10.0 by @dependabot[bot] in #95
  • build(deps): update agentrust-trace-tests requirement from <0.5,>=0.4 to >=0.4.1,<0.5 by @dependabot[bot] in #94
  • Validate manifests across repository layouts by @imran-siddique in #97
  • Declare TRACE integration roles and conformance claims by @imran-siddique in #99
  • Enforce repository compatibility floors by @imran-siddique in #101
  • Generate the integration index from manifests by @imran-siddique in #98
  • Define the third-party appraisal contract by @imran-siddique in #102
  • Automate integration maintenance checks by @imran-siddique in #103
  • Add isolated first-party test environments by @imran-siddique in #100
  • Add OpenShell TRACE evidence adapter by @imran-siddique in #112
  • Fix OpenShell v0.0.105 compatibility and prepare adapter release by @imran-siddique in #113

New Contributors

Full Changelog: capture-core-v0.1.0...trace-adapters-v0.1.0

capture-core-v0.1.0

Choose a tag to compare

@github-actions github-actions released this 01 Aug 04:36
f6f5b34

What's Changed

  • spendguard: Agentic SpendGuard × TRACE integration (fills scaffold-spendguard) by @m24927605 in #30
  • docs(claude-code): add PRIVACY.md by @imran-siddique in #44
  • feat(codex): add AgenTrust agent integrity plugin by @carloshvp in #45
  • feat(scheduled-agents): agent-integrity for Claude Code scheduled agents by @imran-siddique in #52
  • build(deps): bump actions/setup-python from 5.6.0 to 7.0.0 by @dependabot[bot] in #47
  • build(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in #49
  • build(deps): bump fastapi from 0.139.0 to 0.139.2 by @dependabot[bot] in #50
  • build(deps): bump actions/checkout from 4.3.1 to 7.0.1 by @dependabot[bot] in #48
  • feat: add comply54 → TRACE v0.1 integration (Level 0, African regulatory compliance) by @kingztech2019 in #11
  • feat(sentinel): Agent Sentinel as a clean, signed TRACE Level 0 integration by @imran-siddique in #53
  • feat(trace): emit the TRACE v0.2 profile URI by @imran-siddique in #60
  • fix(deps): bump every trace pin to the v0.2 cutover by @imran-siddique in #61
  • build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by @dependabot[bot] in #54
  • build(deps): bump actions/setup-python from 6.3.0 to 7.0.0 by @dependabot[bot] in #55
  • build(deps): update agent-manifest requirement from >=0.3 to >=0.7.0 by @dependabot[bot] in #56
  • build(deps): update cryptography requirement from >=42.0.0 to >=42.0.8 by @dependabot[bot] in #57
  • Feat/ramen ai cmcp by @ramen-noodle6 in #51
  • fix(report): never render an unmeasured category as a measured zero by @imran-siddique in #62
  • fix(skills): fingerprint the whole skill directory, not SKILL.md alone by @imran-siddique in #63
  • feat(baseline): tag the baseline so a rewrite is detectable by @imran-siddique in #64
  • fix(codex): digest the whole skill directory, not SKILL.md alone by @imran-siddique in #65
  • feat(core): add agentrust-capture-core and migrate claude-code onto it by @imran-siddique in #66
  • refactor(engines): migrate codex and scheduled-agents onto the capture core by @imran-siddique in #67
  • feat(copilot): add a pull-request integrity check for GitHub Copilot by @imran-siddique in #68
  • docs(copilot): record why no signed artifact is emitted, and file the spec gap by @imran-siddique in #70
  • feat: seal codex and scheduled-agents baselines, and fix the test collision by @imran-siddique in #69
  • feat(core): add the PyPI release workflow, and fix two packaging defects by @imran-siddique in #71

New Contributors

Full Changelog: claude-code-v0.2.0...capture-core-v0.1.0

claude-code v0.2.0

Choose a tag to compare

@imran-siddique imran-siddique released this 16 Jul 18:57
9b782ae

First launch-ready release of the AgenTrust plugin for Claude Code.

Install:
/plugin marketplace add agentrust-io/integrations
/plugin install agentrust-claude-code

What it does: captures what your Claude Code agent IS (skills, permissions, MCP servers, instruction layer, model, each fingerprinted) and what it DID (a signed TRACE record), and warns at the start of every session if anything was added or subtracted since your approved baseline.

Highlights since 0.1.0

  • Persistent Ed25519 signing key + published verification_key.json: the Agent Manifest is now independently verifiable on any machine and tamper-evident.
  • Repo-root marketplace manifest so the plugin actually installs.
  • SessionStart hook hardened against malformed config and corrupt state (never crashes the session; a corrupt baseline self-heals).
  • /manifest verify now catches drift introduced mid-session.
  • CI runs the test suite (stdlib-only + signing on Python 3.11/3.12/3.13).

The SessionStart hook and drift check need only the Python standard library. Signing (/trace, /manifest approve --sign) needs the crypto packages: pip install -r claude-code/requirements.txt.

TRACE records on a normal dev box are software-only / Level 0, not hardware-attested. See the plugin README "Known limits".

Full changelog: claude-code/CHANGELOG.md