Skip to content

0.4.0 - 2026-09-21

Choose a tag to compare

@github-actions github-actions released this 21 Sep 10:09
e1d28f6

Release Notes

Added

  • merge_commit_sha on changes: the commit a merge produced, recorded by the GitHub collector
    for merged pull requests and null otherwise. The key is optional on input, so exports written
    by earlier releases remain valid.

  • A merged change's merge commit is a second attestation subject (<change id>:merge), so an
    attestation is found by the commit reachable from the target branch after a squash or rebase
    merge as well as by the reviewed head. Open changes, and merged changes whose merge commit the
    forge did not report, keep a head subject only.

  • --format in-toto-jsonl: JSON Lines, one unsigned in-toto Statement per change in change ID
    order, each with a manifest covering that change alone as its predicate and unchanged finding
    IDs. Output names ending in .intoto.json, .intoto.jsonl or .jsonl select the attestation
    formats.

  • acc validate accepts an in-toto Statement or JSON Lines of Statements: it checks the Statement
    schema (schemas/statement.schema.json), the predicate type, the predicate as a manifest, and
    that the subjects are exactly those the predicate's changes produce.

  • docs/in-toto.md documents the predicate in the in-toto predicate template;
    docs/design/in-toto-integration.md records the design.

  • acc validate also accepts a Statement whose single subject is the sha256 of the canonical
    predicate, the form GitHub artifact attestations and cosign attest-blob produce, and
    recomputes that digest from the predicate.

  • docs/signing.md: signing the verdict with actions/attest (dogfooded on this repository for
    every merged pull request by .github/workflows/attest.yml) or with cosign, and verifying it
    with gh attestation verify plus acc validate.

  • --attestations PATH (repeatable) on scan, export and pr, and matching action inputs:
    in-toto Statements, DSSE envelopes or Sigstore bundles (.json, .jsonl, files or
    directories) bound to changes by head commit. A Statement of predicate type
    https://noru.tech/spec/ai-change-provenance/provenance/v0.1 establishes agent authorship at
    the explicit tier and must agree with any inline declaration.

  • --verified-by TEXT: the caller's statement of who verified the attestations' signatures,
    recorded verbatim. acc does not verify signatures. Evidence is signed only from a container
    that carried a signature and with a recorded verifier; otherwise the claims are declared.

  • Evidence kind signed, the trust ordering derived < declared < observed < signed, and an
    attestations record in exports (optional on input) that every signed evidence entry must
    resolve to; validation rejects signed evidence without a signed, verified record (ACV003).

  • Policy keys minimum_authorship_evidence (default derived) and minimum_review_evidence
    (default observed). An operator below the minimum does not name the effective human (ACC006
    fails, independence unknown); an approval below the minimum does not qualify.

  • examples/provenance.intoto.json, the provenance document as a Statement to sign.

  • The review document (schemas/review.schema.json, predicate type
    https://noru.tech/spec/ai-change-provenance/review/v0.1): a signed statement of who
    reviewed what and decided what, naming the reviewer in the predicate. Read by
    --attestations, it upgrades the forge's matching review (evidence becomes signed) and
    never creates one; unmatched documents are recorded with matched: false. For an agent
    reviewer the review records agent (operator, identity, instructions owner, model).

  • --verification PATH (and the verification action input): the JSON that
    gh attestation verify --format json writes, loaded as signed attestations with the signer
    the verifier established (identity and issuer) recorded on the attestation.

  • Agent vendors: agent actors carry vendor from a built-in registry (claude-code →
    anthropic, copilot → github, codex → openai, …) extended by
    --agent-vendor AGENT=VENDOR and the agent-vendor action input.

  • Pull request labels are collected as labels on changes.

  • examples/review.intoto.json.

  • Rules for agent reviewers: ACC007 agent approval recorded (info, an observation), ACC008
    same-vendor write and review (high), ACC009 agent approval lacks required independence
    (high) and ACC010 agent approval without signed identity (warning). ACC007 and ACC008
    evaluate under every policy; ACC009 and ACC010 only under agent_review.

  • The opt-in agent_review policy block (satisfies_independence, require,
    minimum_evidence, labels). When on, a signed agent approval independent of the effective
    author on every required dimension (operator, provider, identity; instructions opt-in)
    satisfies ACC001 and ACC003 with a reason that names the policy. Unknown on a required
    dimension never yields a clean result. Default policy behaviour is unchanged.

  • Fixtures agent-review-* for every case of the agent-reviewer design's worked table; fixture
    directories may carry a policy.yml.

Changed

  • Specification 0.2. The second form of qualifying approval under agent_review (§6.1),
    the independence dimensions (§6.5), ACC007 to ACC010 (§6.2), version compatibility (§12).
    Manifests and the resolved policy are version 0.2; exports and policies written as 0.1
    remain valid input. The attestation predicate type is
    https://noru.tech/spec/ai-change-provenance/v0.2; the provenance and review documents stay
    at 0.1. Earlier in this release: specification 0.1 revision 3 (§4 merge commit, §7.3
    attestation forms and the verifier's subject check), revision 4 (§3.2 provenance
    attestations, §3.6 evidence strength and pre-verified input, §6.3 evidence minimums) and
    revision 5 (§3.7 review document, signer records, vendors, labels).

Install agent-change-control 0.4.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.4.0/agent-change-control-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/acc

Download agent-change-control 0.4.0

File Platform Checksum
agent-change-control-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
agent-change-control-x86_64-apple-darwin.tar.xz Intel macOS checksum
agent-change-control-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
agent-change-control-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-control

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control