Skip to content

agentrust-trace 0.11.0

Latest

Choose a tag to compare

@imran-siddique imran-siddique released this 25 Sep 23:29
· 27 commits to main since this release
7d8df34

agentrust-trace 0.11.0

Breaking

  • TraceAGTAdapter and TraceSandboxAdapter require enforcement_mode. They used to default to enforce, which signed a claim that a policy was evaluated when nothing evaluated it. Callers pass the mode their runtime ran under, or declared when no engine evaluated the policy (#416, #419; diagnosis and first fix by @solloek369-arch in #417).
  • Signatures accept only canonical unpadded base64url, so one signature has one spelling. A padded or non-canonical signature that used to decode is refused (#418).

Added

  • verify_record() reports whether the objects a record cites resolve (#374).
  • Verifiers declare accepted_profiles, and VerificationResult records the profile it verified under (#347, for #116).
  • The reproducibility claim and its re-execution appraisal in the schema and models, with 21 signed vectors (#364, #370).
  • condition-appraisal is a registered references relation (#389).
  • MCP Server Provenance v2 binds behavioral hints (#409).
  • intent_bridge binds a successor observation by digest (#340).
  • provenance.verify_record() takes now to replay a freshness decision (#411).

Fixed

  • Schema patterns follow ECMA-262, so a trailing \n, \r, U+2028 or U+2029 no longer passes subject or URI checks (#388). The Pydantic models share the same patterns (#412).
  • A malformed signature is reported as malformed, not missing (#390).
  • Revocation bundles with no RFC 8785 form are unverified_for_revocation rather than an exception (#386).
  • Non-ASCII challenge nonces raise the documented ValueError (#383).
  • The AGT adapter no longer stamps appraisal.status: affirming on every record (#336), and both adapters check iat before signing (#343).
  • The v0.3 draft schema refused neither a private cnf.jwk nor an RSA key with no key material (#372, #311).
  • Input validation across content_marking, provenance, intent_bridge, revocation, the sandbox adapter and sign.verify_record() freshness bounds (#239, #282, #284, #287, #288, #290, #300, #305, #318, #322, #333, #334, #335, #339, #387, #410).
  • The PyPI description named TrustRecord.sign(), record.anchor() and record.verify(), none of which exist. It now shows sign_record and verify_record (#309).

Full list in CHANGELOG.md.