v0.3.0 — Production Foundations
v0.3.0 — Production Foundations
Date: 2026-04-28
Status: Published. All six packages live on npm at 0.3.0,
published via the new release-publish.yml workflow using npm
Trusted Publishing (OIDC) with build provenance attached.
Tagged as v0.3.0 and released on GitHub.
This release is the foundation step on the path to a stable
production AgentBridge v1.0.0. It does not declare
production-readiness — it builds the docs, threat model, allowlist
behavior, and supply-chain plan that v1.0 will depend on. The full
checklist of what v1.0 actually needs is in
docs/v1-readiness.md.
Highlights
- Stricter remote-target allowlist.
AGENTBRIDGE_ALLOWED_TARGET_ORIGINSis the new
production-recommended way to permit non-loopback target hosts.
ExactURL.originmatch. Loopback stays allowed by default.
AGENTBRIDGE_ALLOW_REMOTE=truestill works for testing and now
emits a one-time stderr warning. The strict allowlist always wins. - Configurable bounds. Three new env vars (
AGENTBRIDGE_ACTION_TIMEOUT_MS,
AGENTBRIDGE_MAX_RESPONSE_BYTES,AGENTBRIDGE_CONFIRMATION_TTL_SECONDS)
are clamped to safe ranges and warn on out-of-range / non-integer
input. Defaults are unchanged from v0.2.2. - Stdout hygiene test. A new subprocess test boots the built
MCP server and asserts every stdout line is parseable JSON-RPC
and that warnings are routed to stderr only. - Threat model published. docs/threat-model.md
catalogues 15 threats with current mitigations, gaps, v1.0 targets,
and test pointers. - v1.0 readiness checklist published. docs/v1-readiness.md
pins down what we mean by "production-ready" and what's left. - Production-readiness guide published. docs/production-readiness.md
draws the line between today's safe-for-local and tomorrow's
safe-for-financial-actions, with a pre-flight checklist. - Security configuration reference published. docs/security-configuration.md
is the authoritative env-var table, with bounds, recipes, and
examples for every supported MCP client. - npm Trusted Publishing workflow shipped and exercised.
.github/workflows/release-publish.yml
isworkflow_dispatch-only, defaults todry_run=true, and uses
OIDC instead of a long-livedNPM_TOKEN. Used to publish v0.3.0
end-to-end with provenance — see
docs/trusted-publishing.md.
What you can use today
After upgrading to v0.3.0, the following paths become available:
# Production-recommended: strict origin allowlist, persistent data dir,
# tightened TTL.
export AGENTBRIDGE_ALLOWED_TARGET_ORIGINS=https://staging.app.internal
export AGENTBRIDGE_DATA_DIR=/var/lib/agentbridge/staging
export AGENTBRIDGE_CONFIRMATION_TTL_SECONDS=120
npx -y @marmarlabs/agentbridge-mcp-server# Local dev (unchanged from v0.2.2)
npx -y @marmarlabs/agentbridge-mcp-serverThe agentbridge mcp-config CLI prints these snippets out of the
box and now points at the new docs.
What changed for the safety story
Nothing weakened. Specifically:
- The confirmation gate still refuses every risky action without
confirmationApproved: trueAND a single-use, input-bound
confirmationToken. - Origin pinning still rejects any action endpoint whose
URL.origindiffers from the manifest'sbaseUrl. - Audit redaction still strips
authorization,cookie,
password,token,secret,api_key,apikeyrecursively
before persisting. - The demo app's destructive actions are still simulated.
- Loopback is still the default. Two opt-ins (strict allowlist;
broad escape hatch with stderr warning) are documented.
What's NOT in v0.3.0
- HTTP MCP transport — planned for v0.4.0.
- OAuth / authorization — planned for v0.4.0.
- Signed manifests — planned for v0.5.0.
- Pluggable persistent storage — planned for v0.7.0.
- Policy engine integration — planned for v0.6.0.
- Any new manifest spec changes — schema is stable for v0.x.
Supply-chain status
- v0.2.0 / v0.2.1 / v0.2.2 were published manually with temporary
granular tokens that were revoked after each publish. - v0.3.0 was published via npm Trusted Publishing (OIDC) from
GitHub Actions — noNPM_TOKENsecret was used, no long-lived
publish credentials existed at any point. - Every v0.3.0 tarball carries an SLSA build provenance
attestation
recorded athttps://registry.npmjs.org/-/npm/v1/attestations/<pkg>@0.3.0.
Verifiable on each package's npmjs.com page (look for the green
"Provenance" check) and vianpm view <pkg>@0.3.0 dist.attestations. - The Trusted Publisher records on npm point at
marmar9615-cloud/agentbridge-protocol→
.github/workflows/release-publish.yml, with no environment
scope (so anymain-based dispatch can publish).
Tests
- Existing 87 tests still pass.
- New test files:
apps/mcp-server/src/tests/safety.test.ts
— 20 cases covering loopback default,AGENTBRIDGE_ALLOW_REMOTE
warning, exact-origin allowlist, prefix attacks, port mismatch,
non-http schemes, multi-origin, and allowlist-wins-over-broad
interaction.apps/mcp-server/src/tests/config.test.ts
— 11 cases covering the three configurable bounds: defaults,
in-range values, clamp behavior on too-low / too-high, and
fallback on non-integer input.apps/mcp-server/src/tests/stdio-hygiene.test.ts
— 3 cases covering clean shutdown, JSON-RPC parseability, and
stderr-routing of the broad-remote warning. Builds the dist
on demand inbeforeAll.
How to evaluate v0.3.0 from a clean checkout
git clone https://github.com/marmar9615-cloud/agentbridge-protocol.git
cd agentbridge-protocol
git checkout v0.3.0
npm ci
npm run typecheck:clean
npm test
npm run build
npm run pack:dry-run
npm run smoke:external
node packages/cli/dist/bin.js version # 0.3.0
node packages/cli/dist/bin.js mcp-config # mentions AGENTBRIDGE_ALLOWED_TARGET_ORIGINSThe same gate is documented in
docs/release-checklist.md for the next
release.