Skip to content

bide v0.7.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 21:20
· 132 commits to main since this release
74e7900

Proofs you can hand out, providers you can switch between.

v0.7.0 deepens the audit trail and broadens where bide runs. A proof now reveals only what it proves, every provider adapter speaks its API exactly, and the journal returns byte for byte what it recorded, on every store and across every process.

  • Private, precise proofs. Every journal record and event carries its own salt, so a proof bundle discloses the record it proves and nothing about its neighbours. Signed tree heads commit to their tree's kind and run, evidence packages are sealed and checked field by field, and delegated grants attenuate strictly (issuer, expiry, and every scope key).
  • Earned authority with a current-grant ledger. VerifyCurrentGrant confirms a grant is the latest one issued, against a ledger head the verifier has seen, so a demotion takes effect everywhere.
  • Exact replay. A resumed run sends the model the same bytes the live run did, on MemStore, SQLite, and Postgres alike. agent/durabletest checks any store against this contract.
  • Provider adapters, refined. Requests match each provider's API: grouped Gemini tool results and schemas, Gemini thought signatures and Anthropic redacted thinking carried round-trip, unique tool-call ids on every turn, and max_completion_tokens for OpenAI reasoning models. Quota exhaustion is reported as ErrQuotaExhausted rather than retried, and a turn ends only on the provider's own end-of-turn signal.
  • Durable governance at scale. Governed event logs append idempotently across Redis, SQLite, and Postgres, migrate safely under concurrent opens, and work on Redis Cluster. Each quorum has its own name, and a tie is never agreement.
  • Sagas and sub-agents. Rollback reaches every call a saga started, including ones cut off mid-flight and those inside sub-agents. A pause inside a sub-agent names the root run to continue, a pause in one parallel tool lets its siblings finish, and Recover knows a finished rollback is done.
  • Sessions and flows. Sessions stay consistent across several workers, with each turn tied to its message. plan rejects graph shapes it cannot run as declared, and a run always resumes under the flow it started with.
  • Privacy by default. Traces and ToolLog record an error's category unless content capture is on, URL credentials are redacted from tool errors before they are journaled (WithToolErrorRedactor scrubs more), and signers and adapters never print their keys.
  • Verification you can re-run. Fuzz targets for every parser and verifier run in CI alongside govulncheck, a Benchmark workflow reproduces the published numbers on a standard runner, and How bide is verified describes the discipline behind each guarantee.

API changes:

  • Audit formats move to bide.audit.sth.v4 with versioned, salted leaves; re-anchor heads made with earlier versions. Record gains Salt, and EventLog.Prove returns EventInclusion.
  • VerifyRun, VerifyDelegationChain, SignAbsenceRoot, the absence proofs, EvidencePackage (Seal, WithConsistencyFrom), and earned authority (ProveCurrentGrant, VerifyCurrentGrant) have new signatures.
  • govern.EventLog.Append takes an append id, govern.Quorum takes a name, and bide-audit verify-quorum takes -name.
  • agent.MemWaker.Start returns a channel that closes when it stops, and a model turn with a missing or reused tool-call id is an error.
  • Postgres keeps its journal in the bide_steps table.

Install:

go get github.com/bide-ai/bide@v0.7.0

Docs: https://bide-ai.com