0.4.0 - 2026-09-21
Release Notes
Added
-
merge_commit_shaon changes: the commit a merge produced, recorded by the GitHub collector
for merged pull requests and null otherwise. The key is optional on input, so exports written
by earlier releases remain valid. -
A merged change's merge commit is a second attestation subject (
<change id>:merge), so an
attestation is found by the commit reachable from the target branch after a squash or rebase
merge as well as by the reviewed head. Open changes, and merged changes whose merge commit the
forge did not report, keep a head subject only. -
--format in-toto-jsonl: JSON Lines, one unsigned in-toto Statement per change in change ID
order, each with a manifest covering that change alone as its predicate and unchanged finding
IDs. Output names ending in.intoto.json,.intoto.jsonlor.jsonlselect the attestation
formats. -
acc validateaccepts an in-toto Statement or JSON Lines of Statements: it checks the Statement
schema (schemas/statement.schema.json), the predicate type, the predicate as a manifest, and
that the subjects are exactly those the predicate's changes produce. -
docs/in-toto.mddocuments the predicate in the in-toto predicate template;
docs/design/in-toto-integration.mdrecords the design. -
acc validatealso accepts a Statement whose single subject is thesha256of the canonical
predicate, the form GitHub artifact attestations andcosign attest-blobproduce, and
recomputes that digest from the predicate. -
docs/signing.md: signing the verdict withactions/attest(dogfooded on this repository for
every merged pull request by.github/workflows/attest.yml) or with cosign, and verifying it
withgh attestation verifyplusacc validate. -
--attestations PATH(repeatable) onscan,exportandpr, and matching action inputs:
in-toto Statements, DSSE envelopes or Sigstore bundles (.json,.jsonl, files or
directories) bound to changes by head commit. A Statement of predicate type
https://noru.tech/spec/ai-change-provenance/provenance/v0.1establishes agent authorship at
the explicit tier and must agree with any inline declaration. -
--verified-by TEXT: the caller's statement of who verified the attestations' signatures,
recorded verbatim.accdoes not verify signatures. Evidence issignedonly from a container
that carried a signature and with a recorded verifier; otherwise the claims aredeclared. -
Evidence kind
signed, the trust orderingderived < declared < observed < signed, and an
attestationsrecord in exports (optional on input) that everysignedevidence entry must
resolve to; validation rejectssignedevidence without a signed, verified record (ACV003). -
Policy keys
minimum_authorship_evidence(defaultderived) andminimum_review_evidence
(defaultobserved). An operator below the minimum does not name the effective human (ACC006
fails, independence unknown); an approval below the minimum does not qualify. -
examples/provenance.intoto.json, the provenance document as a Statement to sign. -
The review document (
schemas/review.schema.json, predicate type
https://noru.tech/spec/ai-change-provenance/review/v0.1): a signed statement of who
reviewed what and decided what, naming the reviewer in the predicate. Read by
--attestations, it upgrades the forge's matching review (evidence becomessigned) and
never creates one; unmatched documents are recorded withmatched: false. For an agent
reviewer the review recordsagent(operator, identity, instructions owner, model). -
--verification PATH(and theverificationaction input): the JSON that
gh attestation verify --format jsonwrites, loaded as signed attestations with thesigner
the verifier established (identity and issuer) recorded on the attestation. -
Agent vendors: agent actors carry
vendorfrom a built-in registry (claude-code→
anthropic,copilot→github,codex→openai, …) extended by
--agent-vendor AGENT=VENDORand theagent-vendoraction input. -
Pull request labels are collected as
labelson changes. -
examples/review.intoto.json. -
Rules for agent reviewers: ACC007 agent approval recorded (
info, an observation), ACC008
same-vendor write and review (high), ACC009 agent approval lacks required independence
(high) and ACC010 agent approval without signed identity (warning). ACC007 and ACC008
evaluate under every policy; ACC009 and ACC010 only underagent_review. -
The opt-in
agent_reviewpolicy block (satisfies_independence,require,
minimum_evidence,labels). When on, a signed agent approval independent of the effective
author on every required dimension (operator, provider, identity;instructionsopt-in)
satisfies ACC001 and ACC003 with a reason that names the policy. Unknown on a required
dimension never yields a clean result. Default policy behaviour is unchanged. -
Fixtures
agent-review-*for every case of the agent-reviewer design's worked table; fixture
directories may carry apolicy.yml.
Changed
- Specification 0.2. The second form of qualifying approval under
agent_review(§6.1),
the independence dimensions (§6.5), ACC007 to ACC010 (§6.2), version compatibility (§12).
Manifests and the resolved policy are version0.2; exports and policies written as0.1
remain valid input. The attestation predicate type is
https://noru.tech/spec/ai-change-provenance/v0.2; the provenance and review documents stay
at 0.1. Earlier in this release: specification 0.1 revision 3 (§4 merge commit, §7.3
attestation forms and the verifier's subject check), revision 4 (§3.2 provenance
attestations, §3.6 evidence strength and pre-verified input, §6.3 evidence minimums) and
revision 5 (§3.7 review document, signer records, vendors, labels).
Install agent-change-control 0.4.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.4.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.4.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control