0.2.0 - 2026-09-19
Release Notes
Added
--format in-toto: an unsigned in-toto Statement v1 whose subjects are the evaluated changes'
head commits and whose predicate is the manifest, ready for DSSE signing.- A composite GitHub Action (
action.yml) that installs a checksum- and attestation-verified
release, runsacc pron the current pull request, writes SARIF and a job summary, and exposes
the exit code. This repository runs it on its own pull requests. - The AI Change Provenance 0.1 specification (
spec/ai-change-provenance.md), a narrative on why
account-based four-eyes fails for coding agents (docs/four-eyes.md), a control mapping to
SOC 2, ISO/IEC 27001, PCI DSS, NIST SP 800-53 and SSDF (docs/control-mapping.md), a roadmap,
examples, issue and pull request templates, CODEOWNERS and a citation file.
Install agent-change-control 0.2.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.2.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.2.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control