Metis 1.0.1
Metis 1.0.1 hardens plugin security and release integrity without making an unmeasured performance claim.
Highlights:
- pins GitHub Actions and the plugin security scanner to immutable commits
- adds package-lock, Dependabot, and SECURITY policy
- removes scanner false positives while preserving structured process and SQL execution
- strengthens task-ID and worktree path containment
- prevents benchmark verifier children from inheriting the parent environment
- synchronizes package, Codex, Claude, English, Korean, and generated release metadata at 1.0.1
Release evidence:
- exact commit:
265cf01b6efc6f35f9b51d4399ef3ebb846a9340 - PR: #1
- main CI and security scan: passed on Ubuntu, macOS, and Plugin Security Scan
- tag CI: https://github.com/gkrtjd99/Metis/actions/runs/31864268282
- local
npm run check: 433 tests, 431 passed, 0 failed, 2 environment skips - plugin-scanner 2.0.1116: policy PASS, effective score 89, critical/high 0
- npm package smoke: 187 files; install, CLI help, and public ESM import passed
SHA-256:
Metis-1.0.1.tar.gz:36b0d2f5cb0ce723059f76111921ea4d25979217df12ec7b07271174576c6663metis-orchestrator-1.0.1.tgz:2f1ddb516ae9b83b2cd637624305d5feed1195abdc3beaca9ab1dd85cc5e0315
The npm registry package is not published by this release. Codex, Claude Code, and OpenCode remain adapter previews until release-environment native-host evidence is recorded.