v0.3.3
Fixes mTLS worker identity propagation and certificate rotation for pull-only workers. Retained engine clients also replace their TLS pools after rotation instead of sending a replacement token over an old certificate. Discovery authority stays on the connection rather than changing process environment variables, and a cached certificate identity cannot be reused for another authority.
Upgrade Python/TypeScript bindings to releases using core 0.3.3 before enabling mTLS. Bearer authentication remains the default and retains its existing identity behavior.
Validation: 345 all-feature Rust tests and 6 doctests, formatting and Clippy passed. The real three-SDK source test passed certificate renewal, lost-response recovery, persisted identity, network interruption, runtime restart, revoked bootstrap credentials and post-restart execution. It also passed native-event delivery and a 35-item scored offline Eval across runtime restart and callback outage. Registry-installed qualification is tracked in the coordinated parent PR.