Skip to content

Releases: kl3574/deep-research

v0.8.1

Choose a tag to compare

@kl3574 kl3574 released this 13 Aug 11:20

v0.8.1 release notes

Evidence cutoff: 2026-08-13

v0.8.1 carries forward the bounded research-workflow hardening prepared for
v0.8.0 and replaces its unsafe documentation-only install loop with a tested,
transactional tagged-skill installer. The remote annotated v0.8.0 tag is
retained unchanged for auditability, but it is a withdrawn, unreleased
candidate
: no GitHub Release or XPI asset was published for that tag, and its
README install block must not be executed.

Research workflow changes carried forward

  • Twelve default Codex skills, including the new
    research-workflow-retrospective skill.
  • A deterministic ReportCitationAudit/v1 helper and an opt-in, typed,
    raw-hash-pinned completion gate for substantial governed reports.
  • Stronger learn-from-papers collection, reviewed gap-selection, scientific
    appraisal, network-patch, public redaction, and Zotero projection contracts.
  • A bounded agentic-research systems comparison and a five-incident real-case
    retrospective. These are not universal product benchmarks or proof that a
    report is factually complete.

The detailed scientific and contract-level change inventory remains in the
v0.8.0 candidate notes; v0.8.1 changes the delivery mechanism,
not those bounded evidence claims.

Transactional tagged-skill installation

The new scripts/install_tagged_skills.py installer:

  • creates and holds a mode-0600 sibling lock, then verifies an annotated local
    tag, its peeled commit, HEAD, a clean checkout, and matching bounded
    git ls-remote tag-object and peeled-commit IDs before creating the
    transaction backup, staging, or exchanging the loader root;
  • stages a complete copy of the active skills root directly at the unique
    transaction backup's final recovery pathname on the same filesystem, so
    unrelated installed skills are preserved and successful commit needs no
    post-check archive rename;
  • rejects symlinks and special files in each release skill and compares
    path/mode/SHA-256 manifests before and after installation;
  • uses a Linux renameat2(RENAME_EXCHANGE) whole-root exchange, eliminating
    per-skill loader gaps and directory-nesting ambiguity;
  • rolls the root back on failed post-install verification while transaction
    identities remain bound; if a transaction gate observes external pathname
    drift and the state is ambiguous, it fails closed without deleting unknown
    directories and emits a protected prior-root recovery locator or mode-0700
    recovery copy. The sibling lock and identity gates cover concurrent installers
    and accidental drift; they are not a security boundary against a malicious
    same-user process with unrestricted filesystem access. After success it keeps
    the prior root and retained tag-object source snapshot in a unique external
    mode-0700 backup; neither is recursively cleaned up by the success path;
  • validates all twelve exact SKILL.md locators using a fresh
    codex debug prompt-input process, then records a compact codex-loaders.json
    receipt containing only public skill names, a locator-set SHA-256, and a bounded
    doctor summary. The accepted doctor summary requires integer schemaVersion=1,
    overallStatus=ok, checks entries keyed by check id with id matching the key
    and status=ok. The exact loader fields are status, skill_count,
    skill_names, and locator_set_sha256; the exact doctor fields are
    schemaVersion, overallStatus, check_count, status_counts, and
    check_ids_sha256. Absolute SKILL.md locators, dynamic check IDs, raw
    prompt/doctor output, diagnostic details, environment values, and stderr are
    never persisted.

The installer intentionally does not install zotero-declarative-bridge; that
skill and its Zotero plugin remain explicit opt-ins.

Release boundary

  • The v0.8.1 tag, GitHub Release, asset download, CI, and local installation
    are not proven by this source document. They must be verified after the tag is
    created, without moving it.
  • Release order is an operator-enforced fail-closed checklist: commit and push
    the release branch, green branch CI for that exact commit, annotated-tag push,
    green tag CI,
    GitHub Release plus XPI upload and downloaded-byte verification, merge to main,
    green main CI, then a clean-tag local installation/readback. The workflow
    automates validation and the tag rehearsal; Release creation, asset readback,
    merge ordering, and the real local installation remain explicit operator steps.
  • The Zotero bridge XPI remains version 0.1.11; its deterministic bytes are
    unchanged, while the external update URL is retargeted to the v0.8.1
    release asset.
  • Local skill installation does not install or activate the Zotero plugin and
    does not prove Zotero cloud sync, research-network completion, or universal
    research quality.

v0.7.0

Choose a tag to compare

@kl3574 kl3574 released this 10 Aug 04:58

v0.7.0 release notes

Public skill integration

  • Adds $evidence-appraisal as the eleventh core skill. It keeps prepared
    appraisal requests, independent review, owner-artifact replay, adversarial
    challenges, and targeted evidence needs fail-closed and content-addressed.
  • Extends public CI with evidence-appraisal seam and adversarial contract tests,
    its quick validation, and package-layout coverage.
  • Keeps the deep-research pipeline aligned with its current 11 stages:
    paper_understanding -> evidence_appraisal -> network_merge.

Operator-visible contract changes

  • Scholar provider execution is fail-closed behind a separate
    ReviewedSearchExecutionAuthorization/v1. Both execute and
    execute-appraisal require the actual request-set and authorization artifact
    files; their raw-byte SHA-256 values are computed by the owner and checked
    against the external authorization pin before transport. Callers that only
    passed in-memory objects or self-reported hashes must migrate.
  • New research-knowledge-network scientific writes are no longer accepted
    without an owner-validated evidence-appraisal package, a network/prestate
    binding, and a reviewed per-operation projection. This applies to claim,
    evidence, relation, and gap-transition mutations. Existing ledgers remain
    readable but are not retroactively represented as appraised.

Zotero bridge compatibility

  • Keeps the Zotero declarative bridge at 0.1.11.
  • Reuses the unchanged deterministic XPI
    zotero-declarative-bridge-0.1.11.xpi with SHA-256
    a5aabab25da4b61d321172524a1e961a27420f5887bcb49c76e04e27c70d037c.
  • Retargets the reviewed public update link to the v0.7.0 repository release.

Release boundary

This document records public release integration only. It does not create a
tag, GitHub release, installation, Zotero mutation, network mutation, or live
provider execution.

v0.6.12

Choose a tag to compare

@kl3574 kl3574 released this 09 Aug 11:50

v0.6.12

  • Harden clean literature notes against collection-routing state and arbitrary custom data attributes.
  • Add evidence-bound countercheck closure rebinding without weakening immutable authority checks.
  • Add append-only, evidence-bound research-network note revision.
  • Align Zotero metadata serializer equivalence across Local API and runtime projections, hashing SHA-256 and MD5 from the same attachment read in bridge 0.1.11.
  • Validate 857 Python tests, 23 Node tests, Ruff, compileall, public-tree privacy, 11 skill layouts, and deterministic XPI bytes.

Bridge XPI SHA-256: a5aabab25da4b61d321172524a1e961a27420f5887bcb49c76e04e27c70d037c.

v0.6.11

Choose a tag to compare

@kl3574 kl3574 released this 09 Aug 08:13

Scope

  • Preserve every existing research-knowledge-network JSONL ledger byte-for-byte and append only canonical suffix records through atomic, fsynced replacement.
  • Add metadata-repair v2 serializer guards and bounded Zotero-managed attachment rename/set-order equivalence while retaining v1 exact-only behavior.
  • Read and hash live attachment bytes, reject path/symlink/identity drift, enforce monotone parent and attachment versions, and make readback-only transactions non-executable.
  • Ship Zotero Declarative Bridge 0.1.10.

Validation

  • Local: 823 Python unittest cases and 21 Node 24 tests passed, plus Ruff 0.15.20, compileall, public-tree privacy including untracked candidates, 11 skill validators, diff allowlist, and deterministic double XPI build.
  • GitHub Actions: exact commit b26b35f752e70d932a29e3cb39522fe39a92e056, run 31302931046, passed on the declared Python 3.10 / Node 24 matrix.

Asset

  • zotero-declarative-bridge-0.1.10.xpi
  • SHA-256: 1168a4088dac8a87d4cb7cb3c5c6d356043c155263de198d0a90a2f3cfb4e2cf

The metadata v2 implementation is release-validated offline and in mocked production paths. A real Zotero 9 readback remains a separate runtime verification and is not claimed by this release.

v0.6.10

Choose a tag to compare

@kl3574 kl3574 released this 09 Aug 06:52

Highlights

  • Adds an orthogonal, evidence-bound Zotero existing-parent metadata repair skill and bridge transaction profile.
  • Adds artifact-bound countercheck closure, selected-only gap review, role-aware corpus refresh, and private atomic outputs.
  • Repairs clean-note curation fingerprints and multi-report dossier digest ordering.

Versions and validation

  • Repository: v0.6.10
  • Zotero declarative bridge: 0.1.9
  • XPI SHA-256: 35c8fc2f7263c46ed5c1dafe45ab849a38b8a581ad04e6201205e69facc2b207
  • GitHub Actions: exact-SHA Validate skills run 31299567491 passed under Node.js 24.

v0.6.9

Choose a tag to compare

@kl3574 kl3574 released this 06 Aug 08:14

Harden Zotero note transactions against post-commit editor races and distinguish committed-unverified outcomes from safe retries.

Add strict Zotero storage-equivalent note readback using schema-9 DOM structure while preserving exact prose, attributes, list order, math-node type/order, and decoded LaTeX payload.

Use the Zotero plugin sandbox DOMParser directly and return structured child_drift errors for true note conflicts.

Repository commit: 162b085
Validate skills CI: https://github.com/kl3574/deep-research/actions/runs/31083974755
Bridge plugin version: 0.1.8
XPI SHA256: 7010a524994caf115d8deb208ac529989789e804017bd18c2613fce710b8d79c

v0.6.8

Choose a tag to compare

@kl3574 kl3574 released this 06 Aug 06:13

Keep synchronized Zotero literature notes limited to publication content by rejecting workflow sentinels, operational metadata fields, metadata-like HTML attributes, and workflow headings.

Preserve ordinary scientific uses of words such as status, hash, predicate, transaction, synchronization, and validator.

Repository commit: d3526e2
Validate skills CI: https://github.com/kl3574/deep-research/actions/runs/31076481286
Bridge plugin version: 0.1.7
XPI SHA256: 31c803d748dc8a1add4c8703f1ad958ef30e07114ce85d113e46e98f94e2c674

v0.6.7

Choose a tag to compare

@kl3574 kl3574 released this 06 Aug 05:44

Reject prose-dominated content in Zotero 9 math nodes while preserving genuine operators, aligned equations, cases, and short labels.

Document fixed-pane formula readability and require UI inspection for clipping or KaTeX errors.

Repository commit: 5eceac7
Validate skills CI: https://github.com/kl3574/deep-research/actions/runs/31074947586
Bridge plugin version: 0.1.7
XPI SHA256: 31c803d748dc8a1add4c8703f1ad958ef30e07114ce85d113e46e98f94e2c674

deep-research v0.6.6

Choose a tag to compare

@kl3574 kl3574 released this 06 Aug 04:56

Chinese decision-oriented shortTitle validation completed against the real 62-item sensitivity corpus.

  • Adds causal-warning, negative-equivalence and bounded causal-determination predicates.
  • Keeps descriptive-only and title-abbreviation rejection.
  • Real private compile-only replay passed 62/62 before publication.
  • Includes all v0.6.5 clean-note, knowledge-network and bridge improvements.

Validated by exact-commit GitHub Actions run 31072581057.

deep-research v0.6.5

Choose a tag to compare

@kl3574 kl3574 released this 06 Aug 04:50

Decision-oriented shortTitle validation hardened against real Chinese scenario:conclusion titles.

  • Accepts grouped normative, negative-boundary, comparative, evidential and contrast conclusions.
  • Retains abbreviation and descriptive-only rejection.
  • Includes all v0.6.4 clean-note, knowledge-network, lifecycle and Zotero bridge improvements.

Validated by exact-commit GitHub Actions run 31072304462.