Releases: kontext-security/kontext
Releases · kontext-security/kontext
Release list
v1.2.0
v1.1.1
v1.1.0
v1.0.1
v1.0.0
1.0.0 (2026-08-04)
⚠ BREAKING CHANGES
- retire legacy managed sessions (#440)
Features
- compute the risk annotation in the decision path and upload it (#428) (2eb0fc9)
- config: negotiate endpoint-config v2 and honour the guardrail switch (#433) (d1cbf28)
- doctor: identify builds by source revision, not version string (#435) (d106002)
- doctor: report core setup health (#441) (e4711d8)
- guard: run the guardrail LLM in the managed daemon too (#436) (fa23eb6)
- observe-mode bash risk classifier (SVM + local guardrail LLM) (#414) (f1a1904)
- retire legacy managed sessions (#440) (f5be064)
- setup: make the local risk model an optional setup step (#444) (938bd18)
- single guardrail LLM (stock Qwen3-0.6B, V2 prompt) replacing the JSON judge (#423) (f7be605)
Bug Fixes
v0.16.0
0.16.0 (2026-07-29)
Features
- add staging brew channel for testing branches against the staging backend (#395) (d2400bc)
- config: sync endpoint configuration independently (#387) (69d72f5)
- ledger: add Decision Fact v1 contract mirror and golden corpus (#416) (9b96cb0)
- ledger: build the decision fact from evaluation outcomes (#417) (7b7847b)
- policy: add Go Cedar decision conformance (#383) (eab6639)
- policy: add Go Cedar evaluator conformance (#382) (3184f5d)
- policy: cache native Cedar deployments (#384) (e6d02c2)
- policy: gate Cedar enforcement cutover (#386) (0ea3fd0)
- policy: observe local Cedar decisions (#385) (02d90ec)
- policy: resolve enforcement from remote rollout mode (#412) (063cf95)
- setup: default self-serve installs to remote mode (#413) (7fc4166)
Bug Fixes
v0.15.1
0.15.1 (2026-07-21)
Bug Fixes
- deps: bump vite to 7.3.5 and esbuild to 0.28.1 for open security alerts (#380) (7ae08ff)
- managed-observe stale-daemon recovery — binary watchdog, status breadcrumb, doctor + --fix (ENG-516) (#373) (eb92ea2)
- managedobserve: log consecutive stream flush failures unconditionally (#394) (068e945)
- managedstream: drain past wide receipt ranges, restore batch limit after reductions (#393) (7b77d80)
- sqlite: chunk ledger IN() queries and guard wide receipt rowid ranges (#392) (45a0f16)
v0.15.0
0.15.0 (2026-07-09)
Features
- add payload capture library (#365) (a4a4d59)
- apply org payload capture mode from the policy snapshot (#367) (c2e5034)
- hubspot provider policy — classifier, sync, dry-run + Cowork bash coverage (#364) (625db1e)
- record captured tool payloads in the local ledger (#366) (37e3fb1)