Skip to content

aegis: v0.11.0-alpha

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Aug 15:21
8486832

0.11.0-alpha (2026-08-11)

Features

  • add kilo/opencode/grok agents + doc-count sync (e0bd752)
  • add opencode/grok/kilo to agent catalog (69bb19d)
  • agent card PID list (#56) (7f1e7b3)
  • agents: add 4 read-only pre-v1.0 audit subagents (c836893)
  • agents: track existing operational agents (auditor/researcher/shipper/ui-designer) (31b8a1e)
  • audit: bound the write buffer and make the loss it causes visible (f750481)
  • audit: bound the write buffer and make the loss it causes visible (17d6ee5)
  • audit: record instanceId on file and network audit entries (3d28557)
  • blocklist: alert-only agent quarantine/watchlist (module only) (74f3cde)
  • blocklist: alert-only agent quarantine/watchlist module (1bac0ee)
  • confirm dialog + own-PID self-guard for process stop (C-10 A) (6291b8a)
  • confirm dialog + own-PID self-guard for process stop (C-10 A) (b1c3fbc)
  • detect: surface WSL-inner and IDE-extension agents (4697ced)
  • detect: WSL + IDE-extension process-invisible detection (05bc4a7)
  • events: surface Event Schema v1 attribution on the Timeline tooltip (fe601cb)
  • expand agent card shows full PID list (#56) (2c9e163)
  • file-watcher: hot read-detect cycle on crown-jewel secret dirs (77297b1)
  • file-watcher: hot read-detect cycle on crown-jewel secret dirs (10s RM poll) (a1d77a7)
  • health: define sensor health state model (273dedc)
  • health: distinguish process scan failure from empty fleet (7461209)
  • health: report degraded sensors instead of a silent all-clear (dd0b3cb)
  • health: track filesystem sensor reliability (0c1afab)
  • health: track network observation reliability (536c06c)
  • integration: wire resource-monitor, token-tracker, blocklist + mount RiskIndex (2d5ba09)
  • integration: wire resource-monitor, token-tracker, blocklist + mount RiskIndex (1c32a58)
  • main: carry instanceId on FileEvent and NetworkConnection (ff7d2a1)
  • main: stamp instanceId on injected pid-0 agents (869bcdf)
  • network: classify every endpoint with a verdict that can be checked (926f7c6)
  • network: endpoint verdicts, Event Schema attribution, demo engine out of the prod bundle (7ea5cc3)
  • network: show the verdict and the rule behind it in the Network panel (66436ad)
  • per-agent token + cost readout in agent card (5379f18)
  • per-agent token + cost readout in agent card (25bbfa3)
  • process-utils: surface OS process start-time (epoch-ms) for PID-reuse guard (0892577)
  • process-utils: surface OS process start-time (epoch-ms) for PID-reuse guard (58acccf)
  • process: identify processes by pid+startTime, not pid alone (5fb84e9)
  • process: identify processes by pid+startTime, not pid alone (4def43b)
  • protection: config-dir monitoring for kilo/opencode/grok (1c3c2d6)
  • protection: config-dir monitoring for kilo/opencode/grok + self-access exemptions (34acce3)
  • renderer: add RiskIndex fleet-wide worst-case risk index component (4471fea)
  • renderer: honest agent-card actions - watchlist, view details, acknowledge (fc1c05b)
  • renderer: honest agent-card actions — watchlist, view details, acknowledge (402d78e)
  • renderer: RiskIndex fleet-wide worst-case risk index component (9006865)
  • renderer: stamp demo payloads with a provenance marker (74886f1)
  • resource-monitor: per-PID CPU/RAM + optional NVIDIA GPU memory (8c14def)
  • resource-monitor: per-PID CPU/RAM + optional NVIDIA GPU memory (2e418d0)
  • risk: weigh a flagged endpoint above an unidentified one (c299a85)
  • scan-loop: add performance.now timing instrumentation under logger.debug scan (508cbe4)
  • scan-loop: timing instrumentation under logger.debug scan (41ddee3)
  • tamper-evident hash-chained audit log (bec42df)
  • tamper-evident hash-chained audit log (b5112d7)
  • token-feed: extensible per-PID token-feed reader + Claude Code adapter (286317e)
  • token-feed: extensible per-PID token-feed reader + Claude Code adapter (6940e5e)
  • token-feed: sum Claude Code subagent transcript usage (5e507b2)
  • token-feed: sum Claude Code subagent transcript usage (2853d0a)
  • token: key cost records by instanceId so a recycled pid starts clean (cd7a7bc)
  • token: key cost records by instanceId so a recycled pid starts clean (9549f59)
  • token: per-agent token + cost tracker (module only) (1830899)
  • token: per-agent token + cost tracker (module only) (f11d8b7)
  • ui: compact muted per-PID list in agent card (1cea61c)
  • ui: compact muted per-PID list in agent card (f20db6d)
  • ui: material icon buttons, larger + higher contrast, drop card glow (7d38c46)
  • ui: material icon PID buttons, more contrast, drop card glow (5a34d4a)
  • win32: honest read-detect via Restart Manager (9639b9f)
  • win32: honest read-detect via Restart Manager (rm-hold events) (89403d5)
  • wire token-feed reader into live scan loop + footer token readout (067aae9)
  • wire token-feed reader into live scan loop + footer token readout (b0ac0ba)

Bug Fixes

  • a11y: Esc closes modals, keyboard fixes (ea484b6)
  • a11y: Esc closes modals, keyboard fixes (7adb97c)
  • a11y: keyboard-accessible kill/suspend + palette commands (2259e48)
  • a11y: keyboard-accessible kill/suspend + palette commands (d4d5b89)
  • add current model pricing (opus-4-8, sonnet-4-6) to token-tracker (01fc959)
  • add current model pricing (opus-4-8, sonnet-4-6) to token-tracker (b65dacf)
  • add reentrancy guard to doProcessScan to prevent overlapping scans (C-02) (2eff148)
  • add reentrancy guard to doProcessScan to prevent overlapping scans (C-02) (6a0e02e)
  • agents: allow auditor to run build/test, deny mutations (400eac4)
  • agents: stop allowlisting shared cloud infrastructure per agent (a6f42e0)
  • attribute file events to owning agent (C-01) (d7c3d83)
  • attribute file events to owning agent (C-01) (dc70e51)
  • attribution: never blame a substitute agent for an unowned file event (609f653)
  • attribution: stop a blank agent name leaking into exports and the LLM prompt (f2f5570)
  • attribution: surface unattributed events to every consumer (a4d4ec0)
  • attribution: three-state attribution — never blame a substitute agent (C-01) (be53e44)
  • build: keep the demo engine out of the production bundle (ae609ce)
  • dedup process-names so each name maps to one agent (C-04) (28bbe2b)
  • dedup process-names so each name maps to one agent (C-04) (4c1b8b6)
  • deps: regenerate lockfile with npm 10 so npm ci can install (065cbcf)
  • deps: regenerate the lockfile with npm 10 so npm ci resolves (a6dccc7)
  • deps: upgrade js-yaml to 5.2.3 (826d094)
  • deps: upgrade js-yaml to 5.2.3 (a91f2e1)
  • detection: track agent sessions across polling gaps (dce2947)
  • events: preserve and isolate file evidence by instance (2015467)
  • honest preset labels + resume own-PID guard test (09f242f)
  • honest preset labels + resume own-PID guard test (7d179aa)
  • hooks: branch-guard skips out-of-repo and gitignored paths (05c53d3)
  • hooks: branch-guard skips out-of-repo and gitignored paths (4d45cb4)
  • identity: stamp instanceId before model attachment (c36967d)
  • main: key the cwd cache on pid and process name (064245e)
  • main: start file watchers when the renderer has already loaded (0ac6d51)
  • polling-gap — eager enter, lazy exit (abea37d)
  • re-queue audit events on flush failure so write errors don't lose logs (C-03) (771b911)
  • re-queue audit events on flush failure so write errors don't lose logs (C-03) (b502ee6)
  • renderer: align risk labels and scales with their semantics (757c92d)
  • renderer: correct SummaryCards agent and risk metrics (a6a5c11)
  • renderer: correct SummaryCards monitoring duration semantics (f29f0f9)
  • renderer: drop explicit .ts extension from fleet-risk import (0b61150)
  • renderer: make Events per minute time-reactive (c825603)
  • renderer: make sensitive summary metric semantically accurate (ddba7bf)
  • renderer: make the summary and risk metrics mean what they say (ddecf91)
  • rules: anchor SC003/SC004/SC007 to basename (C-05) (bbf49fa)
  • rules: anchor SC003/SC004/SC007 to basename (C-05) (fb73b28)
  • seed anomaly-toast tracker on first non-empty scores to prevent toast storm (C-12) (603b82d)
  • seed anomaly-toast tracker on first render to prevent toast storm (C-12) (9e30bb5)
  • skills: safe push target + correct tracked-internals check (89face1)
  • tsconfig: split shared base out of root so the renderer is actually type-checked (8ed4233)
  • tsconfig: split shared base out of root so the renderer is actually type-checked (b3442e3)
  • ui: show unique agent count in Total Agents card (d2b9b73)
  • ui: show unique agent count instead of process count in Total Agents card (c686fe4)
  • ux: drop redundant firstScanDone in demo mode (a41d0c4)
  • ux: empty state when no agents detected (8ba4989)
  • ux: empty state when no agents detected (b52da3d)
  • ux: remove dead palette commands, wire working export (5e6fb41)
  • ux: remove dead palette commands, wire working export (cb60777)
  • watcher: key knownHandles by instanceId so a recycled pid starts clean (ed5946a)
  • watcher: key knownHandles by instanceId so a recycled pid starts clean (64640aa)
  • win32: honest read-detection — probe handle.exe, drop .Modules false-positive (7ac875f)
  • win32: honest read-detection — probe handle.exe, drop .Modules false-positive (6773f72)

Performance

  • file-watcher: bounded-concurrency file handle scan (ca0ce88)
  • file-watcher: bounded-concurrency file handle scan (6.2s->~1.5s) (4698e32)
  • instrument win32 spawn timing (measure-only) (4a3e8b8)
  • instrument win32 spawn timing (measure-only) (d3590e3)
  • radar: cache agent positions, rebuild only on agent change (1a9ca4d)
  • radar: cache agent positions, rebuild only on agent change (0c4b357)
  • virtualize NetworkPanel (content-visibility), stable list keys, cap GroupedFeed (fe9be1e)
  • virtualize NetworkPanel (content-visibility), stable list keys, cap GroupedFeed (976e379)

Code Refactoring

  • complete the identity migration - instance-keyed correlation end to end (e71b3e8)
  • extract RM_CSHARP to rm-csharp.js (97b789c)
  • extract RM_CSHARP to rm-csharp.js (164cb84)
  • extract settings-validation from ipc-handlers (89ff5e2)
  • extract settings-validation from ipc-handlers (a1bc79c)
  • hoist sensitive-dir list to constants (single source of truth) (ad4c4c8)
  • hoist sensitive-dir list to constants (single source of truth) (9fdcd6f)
  • hoist the duplicated instanceId reader and cache-name helper (e207e24)
  • identity: finish the instanceId migration in main (ca0636e)
  • identity: make durable instanceKey definition explicit (5867971)
  • identity: remove residual runtime id fallbacks (1de5d4e)
  • main: key the live anomaly bucket on instanceId (975ed1a)
  • remove dead code (C-19, C-20) (d78759e)
  • remove dead code (C-19, C-20) (c891e60)
  • renderer: correlate risk on the canonical instanceId (222502f)
  • renderer: key acknowledgement by instanceId, keep watchlist name (50f7a5a)
  • renderer: key renderer state on instanceId (steps 8-11) (f32ab4b)
  • renderer: key risk anomaly scores on instanceId (8da38f4)
  • renderer: key timeline trajectory and dedup on instanceId (546e553)
  • renderer: select and focus agents by instanceId (c83b768)

Documentation

  • add master development plan (#142) (9d19214)
  • agents: add Agent Fleet table + /review-v1; track commands/; pre-approve audit inspection cmds (e156975)
  • correct subagent N-line dedup claim to defensive (live smoke: 1 line/id on subagents) (2949f6b)
  • correct subagent N-line dedup claim to defensive (live smoke: 1 line/id on subagents) (780fcfa)
  • correct the IPC tables, risk formula and platform claims against source (56167ad)
  • honest no-hooks positioning, monitor-first, fix TS overstatement (281bf31)
  • honest no-hooks positioning, monitor-first, fix TS overstatement (b5e1b26)
  • launch polish, badges, sync numbers (2b2169c)
  • memory-bank: redact usernames, fix module count, log side-edit lesson (099518f)
  • re-derive every count from source and delete two claims that describe nothing (b500ee6)
  • re-derive every factual claim from source (51 drifts, incl. an IPC table that documented 11 nonexistent channels) (456ce76)
  • re-orient Phase 2 Tier 0 - utilityProcess deferred to Phase 5 (Windows measured async) (0fe64dc)
  • re-orient Phase 2 Tier 0 (measure-gate verdict) (b7bb3b9)
  • record that the anomaly bucket moved to instanceId (3d8129b)
  • record that the renderer identity migration landed (a469690)
  • record the identity recon and the state of the migration (2f49438)
  • record the main-screen numbers recon (fe9317c)
  • resync every count with the code, drop the pre-Svelte plan (99a0b91)
  • resync every count with the code, drop the pre-Svelte plan (b7d43c8)
  • roadmap: define sensor health degraded architecture (2998877)
  • sync agent count 107 -> 110 (caad4e2)
  • sync IPC and test counts after the audit-stats channel landed (743e330)
  • sync IPC and test counts after the audit-stats channel landed (4362e6b)
  • sync remaining agent count (90ca4b5)
  • sync remaining agent count 107 -> 110 (27b0e63)
  • sync test counters with npm test output (1075 pass / 4 skip, 68 files) (76cfdbc)
  • sync test/module/signature counts after instanceId rollout (22970e4)
  • sync test/module/signature counts after instanceId rollout (72054cc)
  • update all metadata to v0.10.0-alpha (82a8a8a)
  • update all metadata to v0.10.0-alpha (707 tests, 23 modules, 43 components) (a08b08f)
  • update rule count 70 → 73 (2e91b26)
  • update screenshots to v0.10.0 Fancy UI (28835d6)
  • update screenshots to v0.10.0 Fancy UI (224fcd3)