v0.5.0 — Signed automatic updates with stable hook trust
Routine runtime and CLI updates now preserve native hook trust. A fixed entry verifies releases signed by the plugin's pinned publisher key, then activates compatible updates for new Tasks. Existing Tasks retain their starting runtime.
Changes
- Automatic background update checks, enabled by default, with a six-hour success interval and bounded execution. No model calls.
- RSA-3072/SHA-256 signatures, runtime integrity checks, bootstrap compatibility checks, replay protection, and retention of the previous verified runtime.
- Local
publisher_updates.py status,on,off,update, androllbackcontrols. - Project-scoped
codex execactivity and optional launcher attribution, plus first-prompt hook-trust reminders, included since the previous GitHub release.
Upgrade
This release introduces a new fixed entry. After installing it, open CLI codex → /hooks, review and trust the changed hooks once, then start a new Task. This permits future signed program changes from the same publisher. Routine compatible runtime updates then require no new grant. New hook events or changes to the entry or signing key still require review; plugin/skill structure changes need a normal plugin update.
The Plugins page can show the installed package version while a newer signed runtime is active. Use python3 scripts/publisher_updates.py status from the installed plugin directory to inspect the actual runtime.
Verification
- 222 local tests and CI across Python 3.10–3.13 passed, including packaging and sensitive-data checks.
- An isolated native Codex installation automatically downloaded and executed the published signed runtime. All 8 hooks remained trusted with identical hashes and no second trust grant; the older Task retained its original runtime.
- A normal package upgrade also preserved hook trust. Invalid signatures, corrupted payloads, rollback, disabled updates, and entry migrations are covered by tests.