Releases: aivcs-io/aivcs
Release list
AIVCS 0.5.2
aivcs 0.4.6
Corrective CLI release from AIVCS Forge commit cbd6cf2a6f1bab6e39115ba4014fe9556c27c6bd863886940bab6dd465e308a8.
Fixed:
- Continue RFC 8628 device polling when issuer wraps authorization_pending in an HTTP Bad Request response.
Also includes:
- OAuth 2.1 PKCE browser login with CSRF state verification
- Issuer selection and short-lived Forge-v2 access tokens
- Refresh handling and scope-aware errors
This release does not change the Kubernetes WIF/OIDC workload path.
aivcs 0.4.5
aivcs 0.4.5
Full OAuth 2.1 PKCE browser login and RFC 8628 device authorization flow for the public CLI.
Highlights
- OAuth 2.1 PKCE + CSRF state verification
- RFC 8628 device flow (
aivcs login --device) - Forge-v2 / issuer selection via
AIVCS_FORGE_URL,AIVCS_ISSUER_URL, or--issuer - Short-lived Forge-v2 access tokens with refresh handling
Requirements (off-cluster)
Set AIVCS_FORGE_URL / AIVCS_ISSUER_URL, or pass --url / --issuer / --device.
Kubernetes WIF/OIDC in-cluster login path is unchanged.
Assets
aivcs-darwin-arm64aivcs-linux-arm64aivcs-linux-x86_64SHA256SUMS
AIVCS 0.4.4
AIVCS 0.4.4
Release v0.4.4 of AIVCS (AI Version Control System).
Changes in 0.4.4
- Forge v2 & Access Service: Fully integrated Forge v2 login and device-flow discovery.
- Proxy Resilience: Double-segment route fallback support across CAS endpoints to seamlessly handle reverse proxies decoding
%2Fpath separators. - Manifest Updates: Workspace version bump and synchronizations across all crates.
Installation Channels
- Homebrew:
brew install aivcs-io/tap/aivcs - Docker:
docker run --rm ghcr.io/aivcs-io/aivcs:0.4.4 --help - Source:
aivcs clone aivcs://aivcs/aivcs
AIVCS 0.4.3
Security release. Every advisory chain below was present in the published v0.4.2 tag.
Dependency advisories
| Crate | From | To | Advisories |
|---|---|---|---|
ammonia |
4.1.2 | 4.1.4 | RUSTSEC-2026-0193, -0213 (XSS) |
crossbeam-epoch |
0.9.18 | 0.9.20 | RUSTSEC-2026-0204 (pointer deref) |
h2 |
0.4.13 | 0.4.16 | RUSTSEC-2026-0258 (unbounded DATA frames) |
quinn-proto |
0.11.13 | 0.11.17 | RUSTSEC-2026-0037, -0185 (DoS) |
rustls-webpki |
0.103.9 | 0.103.14 | RUSTSEC-2026-0049, -0098, -0099, -0104 |
cargo audit now reports zero vulnerabilities.
Twelve informational warnings remain — unmaintained, unsound, and yanked
advisories in transitive dependencies, all upstream and none fixable from this
repository. .cargo/audit.toml documents the single suppression,
RUSTSEC-2026-0235, which is resolved into Cargo.lock but provably never
compiled.
Fixes
The test suite has been broken since v0.4.2 shipped.
version_consistency hardcoded a list of nine crates, three of which
(aivcs-repo, aivcs-auth, aivcs-mcp-gateway) were stripped when the public
distribution was sanitized. cargo test --workspace therefore failed on a clean
checkout of the released tag.
The test now derives its list from workspace.members. That also brought
data-mesh-client under the check for the first time and surfaced a hardcoded
version = "0.1.0" where every other member uses version.workspace = true;
it is now workspace-versioned.
Docs
The README documents the install channels: Homebrew, container image, and
building from source.
AIVCS 0.4.2
Sanitized public source release of AIVCS 0.4.2. This export passed the public filtering governance gate and og-ciso-agent compliance scan before publication. Canonical documentation remains in aivcs://aivcs/code-governance.