v15.0.0
Security: 14.1.0 and earlier accepted deploy receipts signed by keys the registry marked revoked (or carrying revoked_at, or an unknown status): deploy-receipt-token treated every status other than 'retired' as active, so deployGate could allow a deploy on a withdrawn key. This release applies the canonical receipt-verifier key-withdrawal rule before any authorization path; revoked_key and unknown_key_status are new non-repairable gate reasons.
Breaking: DeployGateReason gains revoked_key and unknown_key_status (exhaustive switches must handle them); conflicting V2 configuration now throws instead of being silently reconciled.
Also: a machine-readable remedy (deny-remedy.v1) on refused guardToolCall outcomes; the V2 wire fields the guard actually has are sent, the rest bound as named-absent in posture.