Releases: noru-tech/agent-change-control
Release list
0.6.0 - 2026-10-01
Release Notes
Added
codeql.yml: CodeQL static analysis of the Rust, Python and workflow code on every pull request,
on main and weekly; results go to code scanning.- A stable documentation page for every rule (
docs/rules/ACC001.md…), every validation code
(docs/rules/ACV001.mdtoACV010.md) and the exit codes (docs/exit-codes.md), with an index
atdocs/rules/README.md. Each rule page gives the rule in one sentence, why it matters, every
outcome with its exact reason text, the documented control mapping, a failing and a passing
example on a real fixture, how to fix it and how to record a disposition. - SARIF rule descriptors carry
helpUri, linking each rule to its page. The base URL is one
constant (DOCS_BASE_URL), so the pages can move to a docs site later. - Error messages that name a validation code end with
(see <url>), the code's page. Only the
human-readable stderr line changes; JSON, YAML, SARIF results, manifests and the conformance
result line are unchanged. llms.txtat the repository root (llms.txt convention): whataccis, install commands and
links to the most important pages.docs/openssf-best-practices.md: prepared answers for the OpenSSF Best Practices passing level.- Consistent CLI flags.
--format textis an alias oftablewherevertableis accepted, with
identical bytes. A global-v/--verboseprints extra diagnostics on stderr (resolved policy,
format and destination, counts, whether a token is used); stdout is unchanged. A global
--no-color, and a non-emptyNO_COLOR, switch off color in clap's help and usage errors;
acc's own output was and stays uncolored. acc validate --format text|jsonand--output FILE. JSON is a new machine output: one result
object withvalid,message, andcodeandhelp_uriwhen a validation code applies (README,
"Output formats and exit codes"). Text, the default, is unchanged.acc completions SHELL --output FILEandacc manpage --output FILEwrite to a file.- Errors with a fix and a docs link. The common failures print two more stderr lines after
error: …:help: …(what to do) andsee: <url>(the section ofdocs/exit-codes.md, or the
policy page): a missing or rejected token (exit 5), a rate limit, a forbidden or missing
repository and transport failures (exit 6; a 403 with an exhausted rate limit is told apart from a
permission problem), a missing--repo/GITHUB_REPOSITORY, a bad--since/--until/--as-of
or a reversed window (exit 2), and an invalid policy file (exit 3). An incomplete collection
(exit 4) printswarning: collection incomplete: <reason>with the same lines, unless-q.
Messages, exit codes and every machine-readable output are unchanged.Failuregains optional
hintandseefields. - Zero-config collection:
acc scan(andexport) works with no arguments in a GitHub clone.
GitHub is the default forge (acc scan acme/apiisacc scan github acme/api);OWNER/REPO
defaults toGITHUB_REPOSITORY, else the github.comoriginremote (https, ssh and
git@github.com:forms), whichprnow also falls back to; a missing--untilis now and a
missing--sinceis 30 days before the end, in UTC. The resolved repository and window are
printed on stderr and the window is recorded in the output exactly as if passed, so evaluation
stays deterministic. Only the collecting commands read the clock (ACC_NOWreplaces it in
tests). acc doctor [--online] [--format text|json]: the version, whetherGITHUB_TOKEN/GH_TOKENis
set (never its value), whether the default policy file parses, and the repositoryscanwould
detect.--onlineadds GET-only checks: the token and rate limit (GET /rate_limit) and the
latest release, to report a neweracc; this is the only update check and it never runs on its
own. Exit 0 when healthy, 2 when a check failed. The JSON report is a new machine output
(README).- Release archives carry shell completions (
completions/acc.bash,_acc,acc.fish) and man
pages (man/acc.1and one per subcommand), through cargo-dist'sinclude; the Homebrew formula
installs them (bash_completion,zsh_completion,fish_completion,man1). They are
committed and a test keeps them identical to whataccgenerates. The formula step is a fifth
documented hand edit ofrelease.yml(CONTRIBUTING). ACC_GITHUB_API_URL, testing only: points the binary at the loopback replay server. Only
http://127.0.0.1:PORT/http://localhost:PORTwithout a token is accepted.
Changed
- README: four headings are now the questions people ask ("How do I enforce separation of duties
for AI coding agents?", "What does acc not do?", "How does acc decide whether a change was
independently approved?", "Which rules does acc check?"); the old anchors still resolve. Each
rule in the Rules table links to its page. tests/metadata.rschecks that every rule and validation code has a page and that the
documented action pins name the crate version.
Install agent-change-control 0.6.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.6.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.6.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.5.4 - 2026-10-01
Release Notes
Changed
- Dependencies updated:
jsonschema0.29 → 0.58 (ACV010still names the same violation:
the one 0.29 reported first),sha20.10 → 0.11,base640.22 → 0.23,thiserror2.0.21,
and the pinnedcrate-ci/typosaction to v1.50.3. Output is unchanged;deny.tomlnow allows
theZliblicense (foldhash, throughjsonschema). - Workflows grant write permissions per job instead of workflow-wide:
release.ymlgives
contents: writeonly to the jobs that create and upload the release, andattest.ymland
conformance-release.ymlgiveid-tokenandattestationswrite only to their signing job.
Install agent-change-control 0.5.4
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.4/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.5.4
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.5.3 - 2026-09-30
Release Notes
Distribution, documentation and CI only; no change to the tool's behaviour.
Added
- A CycloneDX SBOM (
agent-change-control.cdx.xml) attached to every release, generated by
cargo-cyclonedxthrough dist (cargo-cyclonedx = true;release.ymlregenerated with dist
0.33.0 and its action pins re-applied). - Every release publishes the crate to crates.io:
release.ymlcallspublish-crate.ymlas a
dist custom publish job after the GitHub Release is up. It uses Trusted Publishing (a
short-lived token fromrust-lang/crates-io-auth-action, no stored secret), skips a version
that is already published, and can be run by hand with a tag as a fallback. scorecard.yml: OpenSSF Scorecard analysis, published to scorecard.dev, with a README badge.KNOWN-LIMITATIONS.md, collecting whataccdoes not do and cannot know.- A feature request issue form, a VHS script for the README recording (
docs/demo.tape), and
weekly grouped Dependabot updates for Cargo dependencies.
Changed
- The crate is published on crates.io as
agent-change-control: README shows its badge and the
cargo binstall/cargo installlines again. Also in the README: a "Verify
before you run" section with the exact attestation and checksum commands; a Trust section;
sections reordered (install first, then quick start, what it does and what it is not). Cargo.toml: a one-sentence description, andin-totoandprovenancekeywords in place of
githubandcli.SECURITY.mdlinks GitHub private vulnerability reporting directly and gives the full
verification commands.
Install agent-change-control 0.5.3
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.3/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.5.3
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.5.2 - 2026-09-29
Release Notes
Conformance suite revision 2 in a signed release. No change to the rules or the output beyond
the recorded tool version.
Added
- Conformance suite revision 2: three vectors for the opt-in
instructionsindependence
dimension (independent, dependent, unknown); 35 accept, 18 reject and 4 incomplete vectors. - Tests that a review attestation naming another agent than a verified account mapping, and a
human reviewer's review attestation naming an operator or instructions, are errors. - The Zenodo concept DOI (10.5281/zenodo.23042500) in
CITATION.cff, a DOI badge and a Citing
section in the README.
Changed
- The self-check and attest workflows run the published 0.5.1.
- The README's spec badge and prose name AI Change Provenance 0.3;
tests/metadata.rsnow
requires every "AI Change Provenance X.Y" in the README and docs to name the current version,
and the DOI to be the same everywhere. - Specification §9 no longer names a single conformance suite revision (0.3 revision 3):
revision 1 was published at v0.5.0, and later revisions only add vectors or correct expected
results.
Install agent-change-control 0.5.2
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.2/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.5.2
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.5.1 - 2026-09-29
Release Notes
The first release archived on Zenodo. No change to the specification, the rules or the output
beyond the recorded tool version.
Added
.zenodo.json: Zenodo archives each published release and mints a DOI, reading the deposit's
metadata from this file;tests/metadata.rskeeps it in agreement withCITATION.cffand
Cargo.toml.
Changed
- The self-check and attest workflows run the published 0.5.0, and the attestations they make
carry thev0.3predicate type. - Version references across the documentation are current: supported versions in
SECURITY.md,
policy examples at0.3, the schema and model descriptions, and editorial wording in the
specification that still said 0.1 (0.3 revision 2, no normative change).
Install agent-change-control 0.5.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.1/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.5.1
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.5.0 - 2026-09-29
Release Notes
AI Change Provenance 0.3: RFC 8785 serialization and I-JSON input. Rules and verdicts are
unchanged; digests and finding identifiers are not.
Changed
- Every byte sequence acc hashes or signs is the RFC 8785 (JCS) serialization of the normalized
value (spec §8.2), through one module (src/canonical). The trailing newline that was part of
every preimage is gone, so finding identifiers,generated.source_digestand thesha256
subject digest change. Every finding, assessment and verdict across the fixture set is the same. - JSON outputs (
--format json,in-toto,sarif, andexport) are written as exactly the JCS
bytes, with no trailing newline, so the SHA-256 of a manifest file is its digest. JSON Lines
keep one newline after each Statement as a separator. - Manifests are version
0.3, the predicate type is
https://noru.tech/spec/ai-change-provenance/v0.3, and exports and resolved policies are
written as0.3. Exports and policies of0.1and0.2remain valid input.
Added
legacy_idson findings: the identifier the same finding had under 0.2, kept for one minor
version.acc checkcarries a disposition over by either identifier.- I-JSON input constraints (spec §8.2), enforced by
evaluate,validate,check, policy
loading and attestation loading: ACV005 non-integer number, ACV006 integer outside
±(2^53 − 1), ACV007 unpaired surrogate, ACV008 duplicate member name, ACV009 nesting deeper
than 128 (rejected without parsing further). acc validatestill accepts ACP 0.2 manifests andv0.2Statements, including attestations
made by acc 0.4.0: it recomputes their digests with the legacy canonicalization and says so.acc evaluate --conformance-json VECTORprints the single-line result object of the
evaluator conformance contract (verdict, failing codes, assessments, manifest digest) and exits
0 evaluated, 3 invalid, 4 incomplete.- The evaluator conformance corpus (
conformance/, spec §9): 32 accept, 18 reject and 4
incomplete vectors under an external-verifier contract, a standard-library Python harness
(run.py) that writesconformance-report.json, a GitHub Action (conformance/action.yml),
and a generatedCORPUS-DIGESTS.txtthatconformance-release.ymlsigns at each tag. Every
reject vector is one mutation of an accept vector. CI runs the corpus againstaccand against
builds with one rule, or the serialization, deliberately broken, and requires those to fail. - ACV010 for input that does not conform to its schema; spec §6.6 lists every validation code.
- CI recomputes the goldens' digests with an independent RFC 8785 implementation in Python
(rfc8785), without acc's code.
Install agent-change-control 0.5.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.5.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.4.0 - 2026-09-21
Release Notes
Added
-
merge_commit_shaon changes: the commit a merge produced, recorded by the GitHub collector
for merged pull requests and null otherwise. The key is optional on input, so exports written
by earlier releases remain valid. -
A merged change's merge commit is a second attestation subject (
<change id>:merge), so an
attestation is found by the commit reachable from the target branch after a squash or rebase
merge as well as by the reviewed head. Open changes, and merged changes whose merge commit the
forge did not report, keep a head subject only. -
--format in-toto-jsonl: JSON Lines, one unsigned in-toto Statement per change in change ID
order, each with a manifest covering that change alone as its predicate and unchanged finding
IDs. Output names ending in.intoto.json,.intoto.jsonlor.jsonlselect the attestation
formats. -
acc validateaccepts an in-toto Statement or JSON Lines of Statements: it checks the Statement
schema (schemas/statement.schema.json), the predicate type, the predicate as a manifest, and
that the subjects are exactly those the predicate's changes produce. -
docs/in-toto.mddocuments the predicate in the in-toto predicate template;
docs/design/in-toto-integration.mdrecords the design. -
acc validatealso accepts a Statement whose single subject is thesha256of the canonical
predicate, the form GitHub artifact attestations andcosign attest-blobproduce, and
recomputes that digest from the predicate. -
docs/signing.md: signing the verdict withactions/attest(dogfooded on this repository for
every merged pull request by.github/workflows/attest.yml) or with cosign, and verifying it
withgh attestation verifyplusacc validate. -
--attestations PATH(repeatable) onscan,exportandpr, and matching action inputs:
in-toto Statements, DSSE envelopes or Sigstore bundles (.json,.jsonl, files or
directories) bound to changes by head commit. A Statement of predicate type
https://noru.tech/spec/ai-change-provenance/provenance/v0.1establishes agent authorship at
the explicit tier and must agree with any inline declaration. -
--verified-by TEXT: the caller's statement of who verified the attestations' signatures,
recorded verbatim.accdoes not verify signatures. Evidence issignedonly from a container
that carried a signature and with a recorded verifier; otherwise the claims aredeclared. -
Evidence kind
signed, the trust orderingderived < declared < observed < signed, and an
attestationsrecord in exports (optional on input) that everysignedevidence entry must
resolve to; validation rejectssignedevidence without a signed, verified record (ACV003). -
Policy keys
minimum_authorship_evidence(defaultderived) andminimum_review_evidence
(defaultobserved). An operator below the minimum does not name the effective human (ACC006
fails, independence unknown); an approval below the minimum does not qualify. -
examples/provenance.intoto.json, the provenance document as a Statement to sign. -
The review document (
schemas/review.schema.json, predicate type
https://noru.tech/spec/ai-change-provenance/review/v0.1): a signed statement of who
reviewed what and decided what, naming the reviewer in the predicate. Read by
--attestations, it upgrades the forge's matching review (evidence becomessigned) and
never creates one; unmatched documents are recorded withmatched: false. For an agent
reviewer the review recordsagent(operator, identity, instructions owner, model). -
--verification PATH(and theverificationaction input): the JSON that
gh attestation verify --format jsonwrites, loaded as signed attestations with thesigner
the verifier established (identity and issuer) recorded on the attestation. -
Agent vendors: agent actors carry
vendorfrom a built-in registry (claude-code→
anthropic,copilot→github,codex→openai, …) extended by
--agent-vendor AGENT=VENDORand theagent-vendoraction input. -
Pull request labels are collected as
labelson changes. -
examples/review.intoto.json. -
Rules for agent reviewers: ACC007 agent approval recorded (
info, an observation), ACC008
same-vendor write and review (high), ACC009 agent approval lacks required independence
(high) and ACC010 agent approval without signed identity (warning). ACC007 and ACC008
evaluate under every policy; ACC009 and ACC010 only underagent_review. -
The opt-in
agent_reviewpolicy block (satisfies_independence,require,
minimum_evidence,labels). When on, a signed agent approval independent of the effective
author on every required dimension (operator, provider, identity;instructionsopt-in)
satisfies ACC001 and ACC003 with a reason that names the policy. Unknown on a required
dimension never yields a clean result. Default policy behaviour is unchanged. -
Fixtures
agent-review-*for every case of the agent-reviewer design's worked table; fixture
directories may carry apolicy.yml.
Changed
- Specification 0.2. The second form of qualifying approval under
agent_review(§6.1),
the independence dimensions (§6.5), ACC007 to ACC010 (§6.2), version compatibility (§12).
Manifests and the resolved policy are version0.2; exports and policies written as0.1
remain valid input. The attestation predicate type is
https://noru.tech/spec/ai-change-provenance/v0.2; the provenance and review documents stay
at 0.1. Earlier in this release: specification 0.1 revision 3 (§4 merge commit, §7.3
attestation forms and the verifier's subject check), revision 4 (§3.2 provenance
attestations, §3.6 evidence strength and pre-verified input, §6.3 evidence minimums) and
revision 5 (§3.7 review document, signer records, vendors, labels).
Install agent-change-control 0.4.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.4.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.4.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.3.1 - 2026-09-19
Release Notes
Fixed
- The GitHub Action's description is under the Marketplace's 125-character limit, so the action
can be listed. No functional change.
Install agent-change-control 0.3.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.3.1/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.3.1
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.3.0 - 2026-09-19
Release Notes
Added
- A derived evidence tier below declarations: vendor
Co-Authored-Bytrailers (built-in registry
for Claude Code and Copilot,--agent-trailer EMAIL=AGENTto extend,--ignore-trailersto
disable) and Agent Trace records (--agent-trace PATH) bound to a change's commits by
vcs.revision. Both yieldderivedconfidence; the operator is derived only when one human
account authored every commit. Declarations and account mappings take precedence, and derived
records naming two agents are not interpreted. Evidence sourcescommit_trailerand
agent_trace; the table marks derived operators. - Matching
agent-trailer,ignore-trailersandagent-traceinputs on the GitHub Action. - Specification 0.1 revision 2: §3.4 derived evidence, §11 relationship to Agent Trace.
Changed
- The repository's self-check now installs the published 0.2.0 release.
Install agent-change-control 0.3.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.3.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.3.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control0.2.0 - 2026-09-19
Release Notes
Added
--format in-toto: an unsigned in-toto Statement v1 whose subjects are the evaluated changes'
head commits and whose predicate is the manifest, ready for DSSE signing.- A composite GitHub Action (
action.yml) that installs a checksum- and attestation-verified
release, runsacc pron the current pull request, writes SARIF and a job summary, and exposes
the exit code. This repository runs it on its own pull requests. - The AI Change Provenance 0.1 specification (
spec/ai-change-provenance.md), a narrative on why
account-based four-eyes fails for coding agents (docs/four-eyes.md), a control mapping to
SOC 2, ISO/IEC 27001, PCI DSS, NIST SP 800-53 and SSDF (docs/control-mapping.md), a roadmap,
examples, issue and pull request templates, CODEOWNERS and a citation file.
Install agent-change-control 0.2.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.2.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.2.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control