0.56.0 - 2026-08-05
Release Notes
Added
-
Boards and the local coding fleet are now first-class agent automation surfaces (Decision
0010; C-547, A-134, L-130, C-548–C-551, C-242, C-244, C-245, A-117).flux boardexposes
session, repository and workspace scopes; general, planning and execution profiles; Track,
session, Markdown, memory and federated backends; vision, roadmap, decision and design documents;
deterministic Track rendering; and the exact current/history metric cube.flux fleetexposes
durable local sub-agent scheduling, acknowledged control, bounded inspection, handoff/rework/gate
records and explicit local-only apply. Both families share theflux.cli/v1JSON/NDJSON contract,
optimistic revisions, idempotent mutations, dry runs, schemas and concise rendered Agent Skills.
BoardId,BoardRef, independent scope/profile/backend contracts andBoardRegistryare public
through the datasource/capability/SDK seams, and Flux-Lang has a first-class closedboard
declaration. The new Coding / AI-assisted development documentation ties the complete workflow
together for humans, Claude and Codex. Neither fleet run nor apply pushes, publishes, releases,
deploys or automatically deletes worktrees. -
Autonomy is now a named posture rather than an absence of safety (C-463).
flux_runtime::AutonomyPosturenames four choices —supervised,bounded-autonomy,
exploratoryandrefusing— and each one selects its approval stance, sandbox floor and budget
together as a single coherent value, instead of leaving them to three independently settable
flags. That coupling is the point: a posture that set approval without also setting confinement
would be C-444's bug with a nicer name. Selectable as--postureon the CLI and
ClientBuilder::posture()in the SDK.--yesandauto_approveare unchanged and map onto
bounded-autonomy; contradictory combinations are refused rather than silently resolved. The set
is a fixed four with no builder — deliberately not an extensible preset generator. Authorization,
guarded IO and evidence recording are invariant across all four, asserted by tests that drive the
same ungranted operation and the same workspace escape through every posture, including those
whose approver allows everything. Each posture documents what it does not protect against, and
no surface presents an autonomous posture as degraded. -
flux reviewnow shows live progress while its built-in review flow runs (C-530). The CLI can
render an interactive reviewer tree, append-only summaries, or no progress via
--progress auto|tree|plain|off; progress stays on stderr so Markdown and JSON reports remain clean
on stdout. The SDK's shared sink-backed flow runner forwards both direct operation events and
correlated child-agent activity without bypassing the normal execution envelope. -
flow_runcan execute Flux-Lang supplied directly in its request. The new mutually exclusive
inline_programaddress is parsed and revalidated against the live operation catalog, then runs
through the same session, approval, guarded-IO, input-seeding, and reentry boundaries as stored
names and workspace paths. Inline route receipts report no resolved filesystem path. -
Independent native gather calls from one model response now execute concurrently (C-528).
Model stages and adaptive exploration share one batch scheduler that admits only idempotent,
low-risk, non-mutating calls with explicit read-only effects and an approval-free authorization
verdict. Pre-tool hooks, active cassettes, approval-sensitive calls, incomplete connector
Network-without-Readmetadata, and every captured action remain ordered. Results retain the
provider's call order and ids across completion, refusal, failure and queue timeout; execution
still crosses the existing authorization, approval, cancellation, redaction, guarded-IO and
max_concurrent_tool_callsenvelope. -
A tracked Flux-Lang writer role now authors checked
.fluxsources (C-513).
.flux/agents/flux-lang-writer.mduses the coding profile and an explicit tool allow-list, reads
the repository language contract before editing, and separates parse/analyze checks from an
explicitly requested run through the ordinary guarded runtime. The public agent catalogue now
links every embedded fallback and tracked project role to its canonical source, with a census
test that detects inventory drift. The role narrows delegated capabilities; it does not create a
new authority boundary. -
Flux now embeds the Exchange Service Account client for official integrations (C-503).
Operator-only environment configuration binds one Exchange origin and bearer; its authenticated
effective catalogue is adopted between turns and one-shot operations run through Exchange's HTTP
invokecontract. Exchange retains credential, tenant, connection, grant and runtime authority.
An outage withdraws only Exchange operations, leaves core Flux usable, and never selects a local
or plugin fallback. Streaming, subscriptions, cancellation frames, terminal lifecycle and leases
remain outside this first slice. -
Running REPL sessions can adopt a plugin's refreshed operation catalog at the next turn
boundary (C-318)./plugin-refresh <name>publishes one atomic generation shared by prompting,
validation, authorization and dispatch. Mid-turn and already-running calls retain their original
catalog; withdrawals, wildcard disables, nested runtimes and newly spawned children all preserve
their existing authority ceilings. A refused refresh leaves both the retained plugin and the
published generation unchanged. -
Flux-Lang supports JSON-quoted object keys in field paths (C-320). Expressions such as
$response.headers["content-type"]and their optional?form preserve the existing strict-field
diagnostics, distinguish quoted numeric keys from array indexes, round-trip through the formatter,
and are mirrored in Prism, tree-sitter, TextMate and IntelliJ.
Changed
-
Every Fleet worker turn now retains its admitted capability ceiling (C-565). Template or
ad-hoc admission normalizes named capability bundles into an exact host-enforced operation set
plus mode, writable/read roots and fences. Missing required capabilities fail before a model
turn; message, restart, resume and rework reconstruct the stored contract instead of reloading a
possibly wider template. Nested tasks can narrow but not widen the active scope. Durable state
and receipts expose a bounded capability-set digest and counts without storing the full operation
catalogue, paths or prompt body. -
Fleet story workers now start with assignment-only context (C-566). A new writer gets a fresh
worker-specific store plus its configured writer contract, exact BoardRef, pinned base, branch and
isolated worktree; the main conversation, intake text, Fleet-wide goal set and other assignments
are not copied into its prompt, and sibling repository roots are not mounted automatically. Only
a turn addressed to that worker can continue its session.
Receipts carry a bounded context-origin manifest with assignment/contract digests instead of
prompt content. -
Automatic Flux releases no longer depend on a model provider account (C-251). The release
workflow now runs the host-onlyexamples/release-cut.flux, consumes the reviewed
[Unreleased]notes already in the repository, and preserves the exact version, protocol,
transaction, candidate-receipt and publication gates. Model selection, Anthropic/OpenRouter/OpenAI
credentials and live-provider smoke are absent from the automatic path, and the parsed authority
policy rejects their reintroduction. The candidate gate also fetches the complete locked
dependency graph before its offline architecture checks, including packages used only by other
compilation targets. -
The v0.56.0 release path now runs from the repository's existing Actions secrets without a
dedicated GitHub App, release Environments, rulesets or branch protection (C-559; supersedes the
C-353 configuration proposal and the matching C-354/C-516 identity clauses). Plan, cut, build,
receipt and verification work remains mutation-credential-free.RELEASE_TOKENis scoped
to the isolated core promotion, plugin tag-control and GitHub Release steps; it preflights before
mutation and performs the exact cut, fast-forward main merge, candidate and tag ref pushes so both
tag workflows run. The ambientGITHUB_TOKENowns only exact cut-CI/candidate dispatch and
Actions observation, with repository contents kept read-only. Parsed adversarial
fixtures reject secret scope drift, model/build exposure, ambient-token tag creation, missing PAT
tag triggering, combined publication authority and any restored App/Environment dependency. -
Operation execution placement is now explicit per operation (C-478). The runtime distinguishes
local control-plane work, selected-execution-system effects, and native-system-only effects. Remote
catalogs retain compatible members of mixed packs, hide native-only operations, and repeat the
same fail-closed check at dispatch; unannotated extensions default to native-only remotely while
local execution remains unchanged./toolsreports the incompatibility reason, and a production
census keeps every built-in classification deliberate. -
Fenced Markdown code blocks now carry a structural
▎gutter (C-537). The shared layout
path applies it to every code row, including blank and list-nested rows, so terminal, ANSI, export,
and monochrome rendering identify code blocks consistently without relying on color. -
Every release authority is now scoped to the explicit job and step that consumes it (C-354,
as superseded by C-559). All
four release workflows declare workflow-levelcontents: read; any other GitHub write permission
is granted on the one job that needs it, and no workflow- or job-levelenvcarries a provider
key,RELEASE_TOKEN,MINISIGN_SECRET_KEYorCARGO_REGISTRY_TOKEN. Pre-tag promotion and
plugin tag control receive the existingRELEASE_TOKENonly on their host-owned steps; signing,
GitHub Release publication and Cargo publication remain distinct tag-triggered jobs, so no job
combines those authorities. Complete cut CI is dispatched on the exact staged SHA; the PAT is not
required to carry Pull requests API scope and the Actions token never moves a ref. Plugin and crates.io
publication accept only an exact tag push — the retained pluginworkflow_dispatchis
structurally a build/validation path that cannot mint a token, create a tag, sign or publish, and
crates-io.ymldropsworkflow_dispatchentirely.scripts/check-release-authority.shenforces
this by parsing the workflow/job/step graph — permissions,on,if,needs,uses, action
inputs andenv— rather than by matching text, with 24 structural fixtures. -
The release-candidate receipt now binds the artifact bytes the publishing run must consume
(C-355). Receiptflux-release-candidate-v3records each of the seven expectedartifacts-*
uploads by API-reported name, immutable database id, size and exactsha256:<64 lowercase hex>
digest in one deterministic encoding; missing, expired, duplicate, malformed or extra artifacts
fail closed, and v2 is not accepted as a compatibility substitute. Promotion downloads each
archive by its receipt-bound id, hashes the raw response bytes and compares identity, size and
digest before opening it, then extracts into a fresh per-record namespace that rejects absolute
paths,..traversal, drive/UNC forms, control characters in names, symlinks and other
special members, duplicate members and cross-archive collisions.merge-multiple: trueis no
longer the trust boundary. -
Core release promotion now binds preview, canonical-main integration and public closure into one
gate (C-516).release_planreads fully framed commit messages and treats a non-empty
[Unreleased]Action neededsection as the pre-1.0 breaking signal, correcting the current
preview from0.55.1to0.56.0. Promotion dispatches completeci.ymlon the exact staged cut
SHA, reconstructs its three-way result against live descendantmain, and pushes one two-parent
fast-forward merge commit before staging that SHA as the candidate and creating the annotated tag
through the isolated PAT-backed promotion step, selects only new exact-tag/SHA workflow runs,
verifies the live Release and whole/releases/latestfleet, and deletes evidence last. The
release trigger is bound to its content-identical canonical-main parent; ifmainadvances during
the cut and checks, promotion accepts only a descendant and reconstructs the exact cut patch in an
isolated Git index against the live main base before candidate creation. A strict up-to-date rule
may add one source-wrapper merge; it is accepted only when it contains the exact release base and
canonical-main parents and is byte-identical to the latter. New Releases have one
exact 28-asset inventory; every archive sidecar and the eleven-entry checksum index are recomputed,
all downloaded bytes must match positive unique GitHub metadata, and every asset must carry the
exact tag/SHA release-workflow attestation. -
The fleet delivery contract now validates one integrated wave instead of every child merge.
A named wave has at most one writer and isolated worktree per story, targeted checks at story
handoff, dependency-ordered integration on one branch, and one unskippable full repository gate
on the final combined tree. Overlapping write sets are serialized, child branches do not open
competing pull requests, and a red gate preserves the failed candidate while publishing nothing.
The still-backlog C-242 contract and its design were corrected before implementation; no runtime
behaviour changed. -
Flux-Lang's authoring-ergonomics roadmap now has implementation contracts for L-131 through
L-140. The wave covers structural type aliases and nested records, typed task outputs and repair
branches, constructors and multiline values, settled fan-out, collecting loops, structured agent
context, and first-classOption/Resultfoundations. This release adds the reviewed contracts,
not those language features. -
Embedded public documentation freshness is now a mandatory PR and publication gate (C-515).
The unfiltered pull-request workflow and exact-SHA release candidate both install the pinned
website dependencies and verifypublic-docs.zip; website publication checks before upload or
deployment. Contributor and release guidance now require regeneration, inclusion of a changed
archive in the same commit, and a post-commit freshness check. -
confirmapproval gates now carry analyzer-derived intent sets. A confirm body now reports
its effective operation names plus host and semantic effects, unknown/failed body analysis remains
explicit, and bodyless confirms are represented as an explicit gate marker. Invalid confirm risk
labels are now rejected by analysis during the normal parse/analyze path. -
Datasources now carry the family's one declared read-only definition (C-514). flux-roadmap
Decision 0006 governs the vocabulary: a datasource is a named, declared, read-only record surface
— operations do; datasources know — with exactly one access mode (indexed or live), one
registry direction across both modes, connector-owned vendor Datasource Definitions,
Exchange-owned tenant bindings and read seam, and a flux-owned wire vocabulary and Flux-Lang
declaration surface. The work board leaves the datasource vocabulary as a first-class
write-capable surface: a new epic charters its ownboarddeclaration,board:subject
namespace and SDK seam, and the Jira/GitLab board stories are re-pointed from the plugin path
Milestone 5 removes onto Exchange-governed operations. The concepts and ecosystem pages (and
their website mirrors), both public datasource pages, and the affected designs — the live-seam
non-goal's named consumers, the discoverability registry disposition, and a partial supersession
of the connector-backed storage facade — were reconciled in the same documentation-only change.
No runtime behavior changed. -
The Exchange environment bearer is now documented as transitional compatibility (C-511).
C-503's lower-level embedded-client setup remains available and redacted, but public and
contributor guidance no longer presents it as the managed Linux-local Milestone 1 bootstrap:
C-509 replaces it there with an Exchange-owned direct handoff into secure storage. Independently
provisioned remote Exchange use retains the configured origin/bearer on every Flux target until a
separate secure remote provisioning contract lands. This Decision 0012 correction changes no
shipped lifecycle behavior. -
Direct dependency changes are now explicit review events (C-450). CI compares each workspace's
exact resolved direct edges with a committed review lock, including which selected packages run a
Cargo build script. Adding, moving, renaming or upgrading a direct dependency now fails with the
exact regeneration command until its lock diff is acknowledged. -
The public security guide now distinguishes secret prevention from containment (C-461). It
identifies connector, host-authentication and non-serializable endpoint guarantees; maps local
program/provider/plugin credentials to their actual materialization paths; and states the
redactor, destination-scope, rotation, audit, and raw prompt/answer durable-log limits without an
unqualified "the model never sees secrets" claim. -
The provider guide now states the supported breadth and the rule for extending it (C-449).
Flux ships eight production text-provider prefixes over four wire codecs plus one optional realtime
implementation; the maintained strategy is a narrow in-tree registry, OpenRouter for the catalogue
tail, and the RustProviderinterface for embedders—not one built-in prefix per vendor or a model
provider loader hidden in connectors/plugins. -
The contributor vision now classifies every decision-bearing finding from the comparative source
review exactly once (C-452). It separates real engineering gaps from deliberate costs of the
mandatory effect envelope and from adoption evidence that code cannot manufacture, with an explicit
purchase and cost for every defended trade-off. -
Canonical and public integration documentation now follows the Exchange-only program (C-501).
The signed plugin pack is documented as temporary compatibility behavior; the future path is one
embedded Service Account client with every official connector runtime executed by Exchange and no
local or plugin fallback. The roadmap now links the cross-repository authority and stages the
one-shot HTTP client before lifecycle, per-adapter proof/deletion, and unconditional plugin
infrastructure removal. This documentation correction does not claim that the client, an adapter
migration, or the zero-plugin release already ships. -
Every long-lived production server and channel listener now binds through the selected guarded
execution system (C-435). Guarded streams split into independent bounded read/write halves so
full-duplex HTTP and SSE remain live under inbound backpressure, including remote HTTPS protocol
v2. The public helpers accepting an already-bound nativeTcpListenerwere removed; single-agent
serving uses its engine's execution system and multi-agent serving now requires one explicitly. -
The cross-repository roadmap now schedules Flux's official-integration migration (C-508).
Decision 0001 makes Exchange the only official execution placement: Flux embeds one Service
Account client, starts with effective-catalogue projection plus one-shot HTTP invocation, and has
no local connector or plugin fallback. The rejected local-host story is closed without
implementation, lifecycle is staged after the useful HTTP slice, adapter deletion remains
evidence-ratcheted, and the final migration removes every plugin artifact and release path. -
A merge from
maininto the dedicatedreleasebranch is now the complete release action
(C-251)..github/workflows/release-flow.ymlruns the deterministic host-only Flux-authored cut,
whilescripts/promote-release-flow.shkeeps the trigger-capable PAT out of the cut step, stages
the exact cut SHA on a versioned candidate ref, verifies its immutable receipt before advancing
main, and waits for both tag workflows plus the public Release verifier. Any failure preserves
the candidate ref and names the recovery evidence instead of leaving a green partial release. The
cut consumes reviewed repository notes and accepts no model/provider credential. Hosted runners
install and self-test bubblewrap before Flux runs its fixed process operations, including enabling
the user-namespace primitive restricted by Ubuntu 24.04's hosted AppArmor default.
They also install the website's locked Node dependencies before the transactional cut, so embedded
documentation regeneration uses the same pinned Docusaurus toolchain as the website gate. The
automated cut no longer repeats the full six-command gate: the exact candidate SHA runs it once,
and the immutable receipt binds that gated commit before main or the tag may move. -
The engineering presentation covers the full runtime story and works as a handout (C-540).
Three new chapters — the adaptive agent loop, sessions as the operational record, and model
strategy — grow the deck to thirteen (about twenty minutes), and its Exchange status now matches
the shipped Service Account seam with snapshots re-verified against both sibling repositories
(connectors v0.20.0, exchange v0.17.0, 2026-08-05). All chapters render in the DOM, so printing
yields a complete handout with a static listing in place of the editor and the Monaco workbench
mounts only when the demo chapter is first shown. Deck keys keep working after activating any
control, touch swipe and a contents menu navigate, browser Back steps chapters, the pipeline
detail follows the site theme, and the footer, landing page, docs overview and README link the
deck — all pinned by the website contract so the deck can neither drift stale nor become an
orphan again. -
Contributor front doors state the adaptive-loop thesis and stop hardcoding release status
(C-529).docs/architecture.md,CONTRIBUTING.mdand the roadmap's Direction section no longer
describe the retired plan-compiler model; a new website-contract test pins the exact retired
sentences out. The roadmap's Next preamble and the story board's Status block become evergreen
pointers instead of version claims (which had rotted 13–17 releases stale), roadmap design links
stay insidedocs/, the public REPL table documents/plugin-refresh, the README's published
topologies link regains its/docs/segment,docs/language.mdpoints at the shipped
Glyph/Railflux projections and quoted-key field paths, the agent-loop and A2A contributor/website
pairs carry reciprocal pointer notes, anddocs/designs/states its convention in a README.
Fixed
-
Native board/fleet real-child tests are hermetic on CI hosts without bubblewrap (C-558). The
Linux-only mock-agent fixture supplies its own test backend instead of depending on the runner's
installed sandbox tools. Production unattended children still fail closed when confinement is
unavailable, and the explicitFLUX_SANDBOX=offkill switch is still not inherited through the
guarded process boundary. -
Workspace boards and Fleet now preserve their repository boundaries during real agent runs.
flux board --scope workspace checkvalidates every configured member, resolves namespaced
dependencies against the federated board and reports the aggregate story count instead of
silently checking only the roadmap checkout. Fleet turns receive every configured repository as
an explicit read-only root while retaining a single writable worktree, and capture now discards
an oversized activity event only at a complete NDJSON line boundary so a later terminal receipt
remains parseable. -
Continued Fleet turns now bound oversized evidence before it can break supervision (C-560).
Adaptive tool results are replaced atomically above 64 KiB, accumulated adaptive history refuses
above 512 KiB and a provider request refuses above 1 MiB with payload-free diagnostics. Fleet
children emit valid source NDJSON lines below 240 KiB; parser defense at 256 KiB preserves a
terminal outcome and records byte counts plus a post-redaction digest instead of slicing JSON.
model.callreports system, schema, text, tool-use and tool-result bytes separately, and Fleet
receipts report stream-budget totals. The hermetic regression reproduces the observed continued
three-repository, 28-operation, six-repair/seventh-request shape without provider credentials. -
The native board-and-fleet release gate now distinguishes fixture literals from executable
build entry points (C-558). The build-ownership scanner ignores standalone Ruby string
predicates and literal-to-literal workflow mutations while still rejecting a real bare
dist build, including an immediately executed generated command. The independently versioned
board contracts movecodewandler-flux-datasource1.3.0 → 1.4.0 (additive public API), while the
new variant on the closed policy resource enum movescodewandler-flux-policy1.0.0 → 2.0.0;
root and plugin dependency floors and both lockfiles now resolve those exact identities. -
Provider-declared quota exhaustion no longer enters transient retry backoff (C-545). Codex,
OpenAI, Anthropic, OpenRouter, and Bedrock can classify explicit usage-limit or credit-exhaustion
responses as terminal, preserving the provider's reset or limit message for the caller. Bare and
otherwise unclassifiable HTTP 429 responses remain retryable. -
The TUI dependency graph no longer carries the unsound
lru 0.12.5release (C-205).
Ratatui, crossterm, ansi-to-tui, the first-party Markdown parity oracles and the maintained
tui-textarea successor now resolve as one ratatui 0.30 generation withlru 0.18.2. The
RUSTSEC-2026-0002exceptions were removed from both advisory gates after root and plugin scans
passed without them. -
Tool results can no longer attach to the wrong transcript card (C-531).
run_callmints a
process-uniqueDispatchIdper call and stamps it on both the call and its result, so
FlowSink::{tool_call, tool_result}andAgentSink::{tool_call, tool_timing, tool_result}now
carry the pairing the durable log already had. The TUI resolvesfinish_tool/time_toolon that
id instead of scanning backwards for the newest same-name card, which cross-attached results as
soon as C-528 admitted concurrent same-nameread/grep/globbatches. The same
name-keyed-collection bug is fixed one layer down in the whatifRerunRecordingSink(FIFO by op
name) and influx-orchestrate'sTextCollector(LIFO by op name, the fleet pane's version of
the same cross-attachment).progress_toolstill matches by name and documents why: a
tool.progressobservation is raised below the interpreter that mints the id, and its only
producer isAccessKind::Process, which the parallel batch scheduler never admits. This is a
breaking signature change on published crates and obliges a workspace MINOR bump. -
A masked host audio socket now fails by name instead of reading zero (D-235). The sandbox
masks/runwith a tmpfs, so argv alone can never reach a PulseAudio/PipeWire socket at
/run/user/<uid>/pulse; the companion[sandbox] writablegrant is now documented as required
rather than optional, in the design, the sidecar docs and the website. Flux also refuses a
configured writable path under/runthat does not exist instead of creating it: an empty
directory bound over the mask applies successfully and still reaches nothing, which turned a
mistyped uid into a silent zero level. The/runtmpfs mask and its invariant are unchanged, and
no environment passthrough was added. -
Tool transcript output is safer and easier to inspect (C-533, C-534, C-536, C-539). Live,
completed, and resumed tool text now consumes escape sequences and drops terminal control bytes
before it reaches a TUI cell. Patch inputs and unified-diff-shaped results render as real hunks
without misclassifying ordinary dash-prefixed prose, wrapped detail rows retain their card rail
and indent, and the TUI and CLI now consume one declared family of truncation budgets while
preserving their intentional surface-specific limits and verbose behavior. -
Repository builds now own their Cargo target while compiler output is live (C-517).
task installacquires one cross-process shared lease before the resolved target is first touched
and retains it across workspace library tests plus both supported binary installs. Every
repository build entry point uses the same persistent sibling lock;task cleanrequires
exclusive ownership and refuses with an actionable diagnostic while builders are active.
Absolute, workspace-relative and fleet-providedCARGO_TARGET_DIRvalues remain reusable, and
Python 3.10+ supplies the pre-Cargo portable bootstrap through native Linux/macOSflockand
WindowsLockFileExbranches. The regression gate reproduces the old deterministic compiler
output disappearance class and separately observes a real bundled-SQLite object under
release/build/libsqlite3-sys-*/outwithout claiming an unobserved incident participant. -
JaaS rooms now close the two residual races in their otherwise-pinned join path (C-413).
Concurrent initial joins are serialized across check, handshake and install so only one session
and pump can be created; a concurrent leave waits for that transition and cannot strand the
session. XMPP-over-WebSocket now resolves once throughflux-systemand performs its handshake on
the exact vetted TCP address, closing the DNS-rebinding gap for the query-carried guest token. -
The CST layout formatter preserves a terminal column-zero module comment (L-125). The LSP's
format-on-save path andfluxlang fmtno longer re-indent a comment after the final declaration
into that declaration's body; exact-text coverage also pins comments before, between, and trailing
on declarations and statements. -
A control-only room-media flood is now counted instead of being shed silently (D-233). Audio
retains its reserved boundary, while the finite control queue exposes a separate loss diagnostic
and the media contract no longer claims that control events can never fill it. -
Room-media settings no longer expose sidecar arguments through
Debugformatting (D-234).
The executable and non-secret timing/buffer settings remain diagnosable, while every argument
afterargv[0]is represented only by a redacted count in both media and containing room output. -
Webhook and connector HTTP ingress now shares the server's body, timeout, request-rate and
concurrency controls (C-409). Admission happens beforeDelivereror task spawn, async work
holds its permit for the full delivery, and refusals reuse the typed429,Retry-Afterand
x-flux-limitvocabulary without retaining credential-derived rate keys. -
The release gate's SDK secure-defaults test is now isolated from an outer Flux sandbox
(C-251). The automatic cut intentionally runs withFLUX_SANDBOX=require; the test now clears and
restores that inherited process policy while asserting the SDK's unset-environment defaults, so a
confined release validates the intended subject instead of mistaking its parent posture for an SDK
regression. -
The Flux-authored release flow now validates the scribe's textual JSON before reading fields
(C-251).release_parse_notesis a pure, strict model-to-host adapter: it normalizes one canonical
jsonMarkdown fence, while surrounding prose, missing or extra fields, and invalid bump opinions
halt before either changelog or the cut script can run. Internal-only releases may still leave the
customer note empty.
flux-cli 0.56.0
Install flux-cli 0.56.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codewandler/flux/releases/download/v0.56.0/flux-cli-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/codewandler/flux/releases/download/v0.56.0/flux-cli-installer.ps1 | iex"Download flux-cli 0.56.0
| File | Platform | Checksum |
|---|---|---|
| flux-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| flux-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| flux-cli-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| flux-cli-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| flux-cli-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
codewandler-flux-lsp 0.56.0
Install codewandler-flux-lsp 0.56.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/codewandler/flux/releases/download/v0.56.0/codewandler-flux-lsp-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/codewandler/flux/releases/download/v0.56.0/codewandler-flux-lsp-installer.ps1 | iex"Download codewandler-flux-lsp 0.56.0
| File | Platform | Checksum |
|---|---|---|
| codewandler-flux-lsp-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| codewandler-flux-lsp-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| codewandler-flux-lsp-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| codewandler-flux-lsp-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| codewandler-flux-lsp-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |