Skip to content

v2.19.0

Latest

Choose a tag to compare

@github-actions github-actions released this 05 Sep 17:32
1e6f2b1

Compatible assurance improvements to collection boundaries, catalog claims,
numerical behavior, operator displays and release reproducibility. No new
collector or model calibration is introduced.

Tool Surface Changes

Tool surface changes: added flag --config-path to recon doctor.

The flag selects the exact client file verified after installation. MCP lookup honors explain=true on
text and Markdown as well as JSON. Plain briefings retain material collection
caveats and sparse-result guidance. Maintainer fingerprint audits default to
built-ins, with explicit --effective-catalog for local additions. Google
identity no longer follows external IdP destinations. Promotion reports bind
the exact evaluated-rule digest and reject unsupported conjunctions and
operator-local rules. Runtime lookup JSON fields and the MCP tool set remain
unchanged.

Fixed

  • Pin HTTP socket destinations to validated public addresses while preserving
    Host, TLS identity, origin pooling, bounded dual-stack fallback, and cleanup
    on cancellation, including an interrupted TLS handshake.
  • Keep Google identity redirects within the documented collector boundary and
    stop inferring federation from Google query-string or path keywords.
  • Reject nested-wrapper ambiguous regex alternations before synchronous
    fingerprint specificity evaluation. Keep simple disjoint literals accepted;
    admission remains conservative and heuristic.
  • Reject special JSON input files before opening them and prevent FIFO-swap
    reads from blocking on platforms with nonblocking file-open support.
  • Bind capsule interpretation context to effective custom/ephemeral catalogs
    and prior overrides. Enforce the capsule write-size bound before temporary
    output creation, preserving existing destinations on failure.
  • Validate review coordinates consistently before collection and retain partial
    catalog diagnostics when source or detector work fails.
  • Use numerically stable, consistent likelihood-ratio ranking. Correct graph
    evidence attribution, Markdown list layout, DOT escaping, and Mermaid custom
    identifiers without claiming calibrated probabilities or additive causal effects.
  • Fail explicitly when a custom Bayesian model underflows or has invalid
    normalization mass, including under optimized Python, instead of emitting a
    fabricated uniform posterior. Ordinary-model parameters remain unchanged.
  • Prevent the maintainer promotion evaluator from treating one rule as support
    for a conjunction or evaluating uncommitted operator-local catalog additions.
  • Filter CNAME discovery candidates against the effective runtime catalog in
    installed wheels, including custom and ephemeral rules, without relying on
    source-only YAML files.
  • Anchor portable-plugin configuration, caches, and state under the client's
    persistent plugin data directory. Prefer connected MCP tools without requiring
    shell access, and distinguish installed-plugin triage from checkout-only
    maintainer workflows.
  • Include numerical-limit regressions in the mutation gate and its change
    triggers, with one-sided underflow and exact-zero arithmetic anchors.
  • Mark per-certificate SAN clipping as graph-construction truncation and use
    the existing deterministic fallback without a misleading seed-stability
    diagnostic. Graph weights, caps, and public fields remain unchanged.
  • Share clean non-match versus unavailable-source labeling across source views,
    preserve caveats in plain briefings, and honor human-format MCP explanations.
  • Resolve only the selected client configuration path, verify explicit profile
    files after installation, and require manager ownership and matching upgrade
    destinations before automatic uv or pipx upgrades. A successful upgrade command
    no longer asserts that the latest PyPI version was installed.
  • Narrow Vercel routes, retire generic AWS-to-SES and unsupported Okta/GitHub
    verification rules, and correct Slack plan and Glitch lifecycle claims.
  • Add exact, dated Retool custom-domain and Postmark return-path CNAME rules,
    with synthetic wrong-owner, lookalike, sparse, wildcard and downstream
    claim-isolation tests. Separately retire two unsupported Postmark CNAME
    suffixes and an SPF owner/target confusion; preserve existing documented SPF
    detection with policy-reference wording. No owner probes are added.
  • Keep batch serialization failures out of successful peer, ecosystem and
    cohort accounting; preserve explicit operator failure states.
  • Clamp model-bound diagnostic inputs before interval arithmetic and normalize
    extreme count vectors without overflow. Keep unavailable support distinct
    from zero, and show the cohort interval method and eligible denominators.
  • Apply DMARC what-if changes to the effective component ledger, including a
    nominal reject policy applied to zero percent of messages. Model weights and
    component ceilings are unchanged.
  • Accept UTF-8 byte-order marks in exclusion lists without changing raw-byte
    commitments. Bind shared rank-sampling implementation files into new round
    execution digests and use unrounded ratios for promotion threshold decisions.
    Explicitly label the evaluator's pooled diagnostic and unexecuted policy text.
  • Wrap narrow terminal rows with aligned continuation text and a single divider,
    preserve CT unavailable/cache/recovery caveats in MCP text, and remove
    magnitude-based security-grade coloring from the aggregate exposure index.
  • Add scripts/release.py --prepare-only for a checked preparation PR without
    a tag or push. Keep rollback bounded to owned files, then tag the exact
    reviewed merged-main commit only after hosted checks pass.
  • Repair optional model-assisted triage to use the built-in inventory, reject
    malformed or incomplete batches before output, preserve same-slug detections,
    and serialize explicitly private pending proposals. No confidence, review
    date or ready-to-promote status is assigned by the model helper.
  • Gate CI on the same built wheel's offline contracts across Windows, Linux,
    and macOS. Release smoke also verifies installed catalogs, MCP resources and
    tools, import origin, executable identity, and portable data relocation without
    adding dependency execution to the isolated build-and-seal job.

Documentation

  • Add repository corpus-planning and catalog-round skills; repair the triage
    skill's typed-summary field and portable-packaging status. Document frozen
    exclusions, untouched holdouts, truthful metrics, and independent review.
  • Reconcile correlation math and diagrams with executable behavior, correct
    historical calibration interpretation, and distinguish default local operation
    from the draft remote adapter's authentication and disk-retention obligations.
  • Clarify the Agent Plugins package root, executable discovery, persistent-state
    isolation, and installation prerequisites. Standards and local protocol checks
    remain distinct from the frozen representative-client evaluation.
  • Correct cache-freshness guidance: internal timestamps are not public lookup
    JSON fields. Document fresh collection routes without implying per-record
    freshness, and reconcile cancelled correlation-study status across documents.
  • Document a consistent operator design language and a dated platform research
    review covering Hermes, OpenClaw, Pi, DeepSeek Harness and NemoClaw. Separate
    documented host capabilities from unrun client qualification and keep the
    frozen representative-client evaluation unchanged.