Releases: flowxo/agent-relay
Release list
Agent Relay 0.1.0-alpha.2
Agent Relay 0.1.0-alpha.2
This prerelease is built from immutable tag v0.1.0-alpha.2 at exact source commit 5649087a5789785737011fab49151287761fb276.
The exact package is published as @flowxo/agent-relay@0.1.0-alpha.2. The intended npm channel is alpha. npm's first-package publication also exposed the same exact prerelease through latest; an authenticated attempt to remove only that extra alias returned HTTP 400, so the alias is recorded rather than hidden. The version, tag, and package bytes were not deleted, moved, or reused.
Integrity and provenance
- Package SHA-256:
d3f5e6dbf33755d7630bd1884ed1ee8286055c0c129e23ddd139e1617875a0c7 - Package size/content: 279,311 bytes; 11 files; 1,770,894 unpacked bytes
- SPDX 2.3 SBOM SHA-256:
e2fd81689bb49959a2a223fd1045241d4b0285491f43b38e66948bc8b7d7aff1 - Package-content snapshot SHA-256:
742e896a62e97c370ae0a0c4ce324b058ebbaedfefde57ff5ac37923d09a75d8 - Release-notes SHA-256:
c35be7eacd31c5505456fad9d03278184a45ad061ce87ed07fcb59ef9bf60d62 - Tagged release-manifest SHA-256:
d6a0699ed76bc8d1c204d4d6a2f42df2fb0d9ebe0326a74986e7ed8c22bebe3b - Tagged SHA256SUMS SHA-256:
f37213a16c17192ed401754c88aef78a6b7c7eff34c241035c582df5e8993ada - Protected build: https://github.com/flowxo/agent-relay/actions/runs/31549946869
- Build provenance attestation: https://github.com/flowxo/agent-relay/attestations/40157521
- SPDX SBOM attestation: https://github.com/flowxo/agent-relay/attestations/40157525
The public npm tarball was downloaded independently and matched the signed workflow tarball exactly by SHA-256, byte size, and npm SHA-512 integrity. The initial interactive package-first bootstrap used the existing GitHub build and SBOM attestations because local npm publication cannot mint CI-provider provenance. The exact trusted publisher is now configured for flowxo/agent-relay, .github/workflows/prerelease.yml, and environment npm-prerelease with publish permission; later publishes require OIDC. The interactive npm session was logged out and no registry token was retained or added to GitHub.
Compatibility and limitations
The supported V1 runtime is macOS on Apple silicon with Node.js 22 or newer. Frozen harness snapshots are Codex CLI codex-cli 0.145.0, Claude Code CLI 2.1.219 (Claude Code), and Cursor CLI 2026.07.23-e383d2b. Other installed harness versions are compatible-unverified.
Native release-exit is not green and is not represented as green. The accepted Low residual also remains: automation cannot prove that every ambient hook was disabled before the invoking shell or GUI began; exact hook-denied isolation and fail-closed aggregate attribution mitigate it. Windows, Linux, and Intel macOS end-user runtimes are not claimed. Cursor IDE late resume and Cursor permission automation remain unsupported. Telegram delivery is at least once across its acknowledgement ambiguity window. There is no automatic dual-send, transport failover, hosted dashboard, or team-policy surface.
The retained live-reviewed package remains the earlier PR #39 alpha.1 tarball; this alpha.2 package is credential-free proof and was not live-tested. No live-provider rerun, production mutation, or live-card authorization occurred for this release.
The attached RELEASE_NOTES.md is the exact generated workflow artifact. Its candidate-status wording records the pre-publication build-time state; this release page records the completed publication outcome.