Skip to content
This repository was archived by the owner on Sep 28, 2026. It is now read-only.

v0.4.0 — LLRT capability boundary hardening

Choose a tag to compare

@robinbraemer robinbraemer released this 17 Jun 09:21
b40b3a3

Packages

  • @robinbraemer/codemode@0.4.0
  • @robinbraemer/llrt@0.2.0
  • @robinbraemer/llrt-* native packages@0.2.0

Highlights

  • Adds explicit data-only and capability executor contracts.
  • Adds LLRT callJsonWithHost manifest execution with no raw global host bridge on the capability path.
  • Routes legacy LLRT function globals through a private manifest namespace.
  • Hardens data-only input validation, host payload/result limits, namespace collision handling, and manifest name validation.

Verification

  • PR #17 passed CI and the full LLRT native package matrix.
  • Local: mise exec -- pnpm run ci.