v0.1.1
This release strengthens default audits with stateful invariant fuzzing, removes implicit third-party evaluation reporting, and updates setup guidance and CI reliability.
- Stateful audits by default. Fresh projects now run all five invariant stages, while exhaustive campaigns can spend four hours fuzzing selected properties.
- More control over evaluation data. Braintrust reporting and the implicit judge gateway are removed; optional judging now requires explicit endpoint and credential configuration.
- Clearer setup and safer maintenance. Documentation matches current configuration and agent behavior, and the ZIP reader update includes upstream archive handling fixes.
Breaking changes
- [evals] [modal] Removes Braintrust reporting and the
eval publishAPI. Optional LLM judging now requiresULTRAFUZZ_EVAL_JUDGE_URLand a dedicated judge key. Modal benchmark configuration moves toultrafuzz.modal.benchmark.v3; existing v2 configurations are rejected and must be regenerated. Thanks @aviggiano! (#1134)
New features
- [config] [runtime] Adds all five invariant stages to fresh default audits and extends exhaustive campaigns to four hours of fuzzing across selected properties, while preserving explicit project and runtime overrides. Thanks @aviggiano! (#1132)
Improvements
- [cli] Updates
adm-zipto 0.6.1, incorporating upstream archive parsing and extraction hardening. Thanks @dependabot! (#1127) - [workflows] [docs] Removes paid benchmark automation and its write-capable history publisher while retaining manual benchmark tools and credential-free CI. Thanks @aviggiano! (#1131)
- [docs] Aligns setup and configuration guidance with current schemas, agents, prerequisites, and Smithers migrations. Thanks @aviggiano! (#1123)
- [docs] [security] Adds private vulnerability reporting guidance and security ownership, and updates the license attribution to Monad Foundation. Thanks @aviggiano! (#1125)
- [evals] Updates the workspace to Vitest 4.1.11 and adapts package tests and fixtures for the new version. Thanks @aviggiano and @dependabot! (#1135, #1121)
Bug fixes
- [workflows] Gives runtime integration and CLI CI lanes up to 120 minutes to finish on slow runners, without changing their coverage or failure gates. Thanks @aviggiano! (#1137)
Full changelog: v0.1.0...v0.1.1