Repository navigation
Froglet 0.4.7-beta.1 — bounded compute and recoverable tasks
Pre-releaseFroglet 0.4.7-beta.1 adds bounded requester-supplied computation and recoverable
task results to the free beta. It is a beta release, not a stable production
qualification.
What changed
- Native MCP compute:
run_computeaccepts a Wasm program and input,
including a local module-path option. The runtime uses the signed
Quote/Deal/Receipt flow and enforces the agreed fuel, memory and execution
limits.get_taskexposes the saved task and its verification evidence. - Optional A2A 1.0 adapter: configured counterparties can submit and poll
tasks using explicit requester keys and exact Offer hashes. The adapter is
disabled by default. Cancellation, streaming and public federation are not
supported in this beta. - Offline terminal-task recovery: completed results and signed terminal
failures remain readable after provider shutdown and requester restart. The
runtime revalidates the cached signed chain, identities, result hash and
terminal status. Corrupt evidence fails closed; pending or unsigned outcomes
still require provider synchronization. Reading a Receipt creates no new
work or payment authorization. - Browser interoperability: the developer playground signs the free
transaction chain in the browser, compiles its AssemblyScript examples
locally in a Worker, and exchanges compatible programs and evidence with a
real node. This does not add JavaScript as a kernel execution runtime. - Research metadata: selected-data declarations expose field types,
namespaces, versions, units and provenance. They compare declared metadata;
they do not establish ontology alignment or scientific correctness.
The canonical kernel artifacts, signing and hashing rules remain unchanged.
Release and dependency checks
Release checks now reject skipped required work, stale or mislabeled local
binaries, incomplete checksums, unexpected archive members and inconsistent
package/Registry versions. Qualification examples use the selected optimized
node without increasing signed execution budgets. CI audits both MCP dependency
trees. Wasmtime is updated to the patched 36.0.17 line; Wrangler 4.143.1 uses
patched Undici.
The website cache library is reviewed at http-cache-semantics 4.3.0. It
preserves the reported max-stale/cookie behavior; upstream disputes the advisory
and closed its proposed fixes unmerged. Its separate Vary fixes and a clean npm
audit do not establish remediation of that behavior. The deployment policy
still verifies the actual static-site/custom-Worker boundary, including on a
clean audit, and fails on other high/critical findings, reviewed-input drift,
a newer stable cache-library version, or expiry on 17 October 2026. See
the dependency review.
Qualification and limits
At note preparation, local software checks, browser/node tests and a deterministic
replay of a previously generated program had passed. The replay includes six
successful signed chains and one execution-limit failure, plus task recovery
with the provider stopped and requester restarted. It does not count as a fresh
LLM generation or agent-host session.
The approved source is d70cb50017c7c526d1f7ad4faf278da07e8248a4. All six
required main CI checks
passed before the beta cut. The release workflow repeats its exact-tag checks
before publishing. Verification and replay through the final published assets
remain separate gates; local checks do not qualify a different released
executable. Consult the release workflow and
qualification record
for the evidence applicable to the source and binary you use.
New hosted compute on independent machines, clean-machine installation,
fresh agent-host journeys, real payment rails and the first-time-user acceptance
gate remain separate qualifications. Existing hosted beta.4 reachability does
not qualify this compute candidate. Signed receipts establish transaction
evidence, not the scientific usefulness or correctness of an answer. A catalog
or service remains dependent on its provider's availability and configured
allowances.
Distribution
This GitHub release path produces native node archives, bootstrap/checksum
assets, an attested Release Bundle and digest-pinned OCI image references.
Verify that bundle before installation or deployment; do not persist mutable
image tags as deployment identities. Select VERSION=v0.4.7-beta.1 explicitly
when using the native installer; this prerelease does not advance the stable
latest channel.
The froglet-mcp npm package and MCP Registry entry are published separately.
An immutable GitHub release does not prove that the matching npm/Registry beta
is available. Check their exact versions before relying on npx froglet-mcp.