Repository navigation
v0.1.2 — gate, packs, records
Moves the CLI from returning probabilities to making decisions: questions are judged by the model, policy is applied offline to a saved answer.
jev ask --pack verify --state-file claim.json --state-format json --record decisions/claim-1.json
jev gate --input decisions/claim-1.json --pack verify; echo "exit $?" # 0 2 3 4
jev replay --record decisions/claim-1.json| exit | decision | caller action |
|---|---|---|
| 0 | accept | proceed |
| 2 | review | escalate |
| 3 | deny | refuse |
| 4 | abstain | not enough information — never acceptance |
Added
jev gate— offline policy evaluation over a saved judgment or record, with per-rule reasons on stdout. Fail-closed: a choice answer needs a normalized probability map (no confidence substitution), a score must sit inside its reported scale, a missing or wrong-typed answer abstains, and a label outsideacceptnever accepts.mode: alltakes the worst outcome (deny > abstain > review > accept); policies are validated on load.- Packs —
verify(claim vs. cited evidence),screen(injection, harmful content, severity, plus substance and relevance for the caller),route(deterministic / specialist / human / none, plus complexity). Each carries a state contract, an embedded policy, and a content hash that records and gate output name. - Records and replay —
--recordwrites model resolved, latency, pack hash, and type-tagged hashes of the state and questions, never the state itself.jev replayre-emits stored answers marked"replayed": true; it is not a rerun. jev doctor [--live]— engine, key presence (never the value), base URL, model, and packs;--liveadds auth, model list, probe latency, and cost.- Offline tooling —
tools/stub-server.mjsfor wiring a pipeline without a key (never claims the requested model, and all three bundled policies deny its answers), andtools/evaluate.mjsfor scoring a policy against labeled records: accuracy, outcome mix, and the support curveaccept_atsits on.
Fixed
- SIGINT/SIGTERM cancellation was dropped: the signal travelled in client options, which ignore it, instead of request options.
batchJSON rows bypassed cost enrichment, so they lacked thecostblock every other JSON response carries.--versionreadspackage.jsonat runtime instead of a hardcoded string.
Publishing
v0.1.1 was tagged at the same commit as v0.1.0 and never reached the registry — its publish run failed with 403 — OIDC permission denied after signing provenance. Trusted-publisher connections created after 2026-09-03 are staging-only, so the workflow now runs npm stage publish and a maintainer approves it with 2FA. v0.1.1 is superseded by this release.
Requires Node.js >= 22.0.0.