Skip to content

v0.4.8

Latest

Choose a tag to compare

@github-actions github-actions released this 31 Aug 22:21
· 4 commits to main since this release
Immutable release. Only release title and notes can be modified.
6184db5

marvisx-cli 0.4.8

This candidate projects the verified public/shared Marvis engine security
refresh into the local single-user product while preserving its CLI, MCP,
hooks, local GUI and package contracts.

The shared source is MarvisX PR #349: reviewed candidate
77c865633b7447c4a778b2569f4ceec9a3b7dce6, merged as
8dfd16e4e275b69435e0348258daf86f67898997. The public product projection is
Marvis PR #70: reviewed candidate
fc747bbda5554b907d93e89b7121d94725e02411, merged as
b96ce42f3331321828dd7f123094b39be07765ac. The release CI foundation is
Marvis PR #71: reviewed candidate
8c5918071652c408c9ff23a268e24016690f6e54, merged as
6cb5bbce045728fce2b0c76b8a45ea0ccacfb15a.

Highlights:

  • requires MCP 1.28.1 or newer, excluding CVE-2026-59950;
  • preserves the public API, CLI, MCP, hooks and local GUI contracts;
  • binds every release stage to reviewed source and exact merged commits;
  • keeps Python 3.10-3.13 and Linux, macOS and Windows coverage;
  • verifies clean install, upgrade, rollback and exact registry bytes.

Versions 0.4.1 through 0.4.7 are burned, unpublished historical attempts
and are never reused. Version 0.4.7 was stopped before PyPI when the security
gate detected the vulnerable MCP dependency.

License: Business Source License 1.1. This is source-available open-core
software and all public descriptions remain bounded by the current BSL terms.

Publication status: active candidate. No package is considered released until
the exact tagged source passes the protected publisher, PyPI byte readback,
clean install, upgrade and rollback gates.