v0.0.20
v0.0.20 hardens Ultrafuzz's execution and artifact boundaries, improves OpenRouter reliability, binds worktrees to immutable launch revisions, and formalizes MIT licensing across the workspace.
- Safer security boundaries. Canonical artifacts now fail closed on detected secrets, while cloud execution, provider environments, archive handling, and governance controls receive defense-in-depth hardening.
- More reliable runs. OpenRouter sessions recover from rate limits without duplicating work, and worktrees stay bound to the exact revision that launched a run.
- Clearer project defaults. The workspace now carries MIT license metadata, a one-hour default agent timeout, and aligned operational documentation.
New features
- [artifacts] [security] Adds a fail-closed publication gate for secret-bearing canonical artifacts, expands credential detection, and makes Kimi credential handling safer. Thanks @aviggiano! (#622)
- [docs] [security] Adds the MIT license, package license metadata across the workspace, licensing documentation, and CI policy checks for release readiness. Thanks @aviggiano! (#657)
Improvements
- [runtime] [security] Hardens governance, cloud execution, provider environment isolation, and runtime-integrity boundaries across high-priority AppSec controls. Thanks @aviggiano! (#635)
- [evals] [security] Bounds evaluation matrices and concurrency, secures remote pricing retrieval against private-address and redirect abuse, and aligns the documented ceilings with the enforced 32-target and 80-row limits. Thanks @aviggiano! (#640, #643)
- [runtime] [modal] Seals governance data used for cloud handoff, strengthens secret isolation, and makes security classification changes fail closed. Thanks @aviggiano! (#644)
- [config] [runtime] Raises the default local and cloud agent timeout from 30 minutes to one hour and documents configuration precedence. Thanks @aviggiano! (#646)
- [runtime] [artifacts] Captures the exact launch revision and binds local, retry, cloud, and workflow worktrees to that immutable source commit. Thanks @aviggiano! (#655)
- [docs] Simplifies the README landing page while retaining the dedicated licensing and security policy documentation. Thanks @aviggiano! (#666)
- [workflows] [runtime] Tiers CI by event so pull requests use a curated runtime smoke suite while pushes to
mainand manual runs retain the full release-validation matrix. Thanks @aviggiano! (#669)
Bug fixes
- [runtime] [openrouter] Recovers safely from initial and mid-run OpenRouter rate limits, resumes the exact session after substantive work, and prevents duplicate or conflicting replay output. Thanks @aviggiano! (#611, #626, #631)
- [cli] [security] Upgrades and hardens benchmark ZIP parsing with bounded archive handling and production dependency-advisory gates. Thanks @aviggiano! (#623)
- [runtime] Declares the generated plain-record validator required by invariant recovery paths and removes the test-only fallback that masked its absence. Thanks @aviggiano! (#668)
Full changelog: v0.0.19...v0.0.20