Wukong Code v0.1.0
Wukong Code 0.1.0
0.1.0 stabilizes the Trusted Local Loop: one controllable, recoverable, and
explainable Goal → Write → Check → Review → Fix workflow. Wukong Code remains
Free, local-first, and BYOK.
What's included
- One editable Preflight for Goal, Done when, Must not, exact checks or an
explicit versioned no-check decision, provider destination, outbound input,
permissions, dirty workspace, iteration limit, provider-call ceilings, and
optional token budget. - Separate approval for local reads, provider transmission, permission mode,
and project-check execution. Cancelling Preflight creates no run and makes no
provider request. - Fail-closed Gate completion: incomplete, stale, conflicting, interrupted, or
corrupt evidence cannot becomePASS. - Deterministic terminal results that separate
PASS,NEEDS_WORK, andERROR
fromPAUSEDandSTOPPED_BY_USER, with decisive evidence, file attribution,
checks, usage, blocker, recovery, and next action. - Enforced provider-call and token ceilings, plus safe reconciliation when a
provider outcome is unknown. - Direct upgrade from
0.0.22, compatibility with0.0.21records, recovery
from crashes and duplicate/late records, and read-only context import from
Codex, Claude Code, Cursor, Kimi Code, and Grok.
Release integrity
The stable release is built from one exact source and catalog identity. The
release workflow verifies six platform archives, adjacent SHA-256 files,
provenance, pinned fresh installs, 0.0.22 upgrades, and state
recovery before and after publication. Published releases are immutable.
The macOS binaries are deliberately not Developer ID signed or notarized.
The installer downloads the matching SHA-256 file, verifies it, and stops before
replacement if verification fails. This is a curl-installed CLI binary, not a
macOS app bundle or installer package.
Install or upgrade
macOS and Linux:
curl -fsSL https://wukong.today/install.sh | sh
wukong --versionExisting native installations can also run:
wukong upgradeWindows users should download the matching x64 or ARM64 ZIP and checksum from
the v0.1.0 release.
Evidence boundary
The immutable 0.1.0-rc.1 candidate passed six-platform build, public asset,
pinned install, 0.0.22 upgrade, recovery, checksum, and provenance
acceptance. The stable release repeats the applicable public checks against the
exact v0.1.0 assets and production surfaces.
The opt-in cohort, first-user comprehension, and real-source workflows remain
valuable post-release product-learning evidence. They are not represented as
completed and do not impose a fixed 14-day waiting gate on this binary release.
Three authorized case studies remain a separate launch/promotion gate.
Full direct-shell content/PATH attestation, a multi-layer coverage schema,
provider pricing, hosted execution, payment, quota, Team, and managed models are
not part of 0.1.0.