Deepr v2.39.0
This release makes spend authority fail closed and keeps paid API dispatch frozen until provider account controls can be proven.
Highlights
- Adds strict home-anchored cost authority, durable reservations, exposure snapshots, and a zero-dollar effective ceiling while paid dispatch is frozen.
- Persists registered legacy accounting roots so source checkouts and installed wheels see the same settled spend and active holds.
- Adds offline provider billing import and reconciliation contracts with explicit provider, scope, and credential evidence.
- Blocks production paid API dispatch until authenticated provider-side budget, overage, and credential identity checks exist.
- Defines an evaluation-first local structured consult graph with exact loopback Ollama confinement, bounded work, layered reduction, explicit completeness, and no paid or plan fallback.
- Tightens the README, refreshes compatible dependencies including AWS CLI 1.45.58 and Boto3 1.43.58, and updates operator and release documentation.
Verified release state
- Unit suite: 9,802 passed, 9 skipped.
- Branch coverage: 85.11 percent against the 80 percent gate.
- Python lint, format, strict type checks, code-health ratchets, frontend tests, frontend build, dependency audits, and secret scanning pass.
- Installed-wheel smoke test sees $41.793757 lifetime settled spend and $38.5240805 for July, with $0 active holds and $0 authorizable paid headroom.
Paid API capacity remains disabled by default. Local execution and deterministically proven no-overage plan capacity remain separate from paid API authority.