Skip to content

Agent Relay 0.1.0-alpha.2

Pre-release
Pre-release

Choose a tag to compare

@PlasticLizard PlasticLizard released this 12 Aug 03:00
· 60 commits to main since this release
5649087

Agent Relay 0.1.0-alpha.2

This prerelease is built from immutable tag v0.1.0-alpha.2 at exact source commit 5649087a5789785737011fab49151287761fb276.

The exact package is published as @flowxo/agent-relay@0.1.0-alpha.2. The intended npm channel is alpha. npm's first-package publication also exposed the same exact prerelease through latest; an authenticated attempt to remove only that extra alias returned HTTP 400, so the alias is recorded rather than hidden. The version, tag, and package bytes were not deleted, moved, or reused.

Integrity and provenance

The public npm tarball was downloaded independently and matched the signed workflow tarball exactly by SHA-256, byte size, and npm SHA-512 integrity. The initial interactive package-first bootstrap used the existing GitHub build and SBOM attestations because local npm publication cannot mint CI-provider provenance. The exact trusted publisher is now configured for flowxo/agent-relay, .github/workflows/prerelease.yml, and environment npm-prerelease with publish permission; later publishes require OIDC. The interactive npm session was logged out and no registry token was retained or added to GitHub.

Compatibility and limitations

The supported V1 runtime is macOS on Apple silicon with Node.js 22 or newer. Frozen harness snapshots are Codex CLI codex-cli 0.145.0, Claude Code CLI 2.1.219 (Claude Code), and Cursor CLI 2026.07.23-e383d2b. Other installed harness versions are compatible-unverified.

Native release-exit is not green and is not represented as green. The accepted Low residual also remains: automation cannot prove that every ambient hook was disabled before the invoking shell or GUI began; exact hook-denied isolation and fail-closed aggregate attribution mitigate it. Windows, Linux, and Intel macOS end-user runtimes are not claimed. Cursor IDE late resume and Cursor permission automation remain unsupported. Telegram delivery is at least once across its acknowledgement ambiguity window. There is no automatic dual-send, transport failover, hosted dashboard, or team-policy surface.

The retained live-reviewed package remains the earlier PR #39 alpha.1 tarball; this alpha.2 package is credential-free proof and was not live-tested. No live-provider rerun, production mutation, or live-card authorization occurred for this release.

The attached RELEASE_NOTES.md is the exact generated workflow artifact. Its candidate-status wording records the pre-publication build-time state; this release page records the completed publication outcome.