0.5.0 - 2026-09-29
Release Notes
AI Change Provenance 0.3: RFC 8785 serialization and I-JSON input. Rules and verdicts are
unchanged; digests and finding identifiers are not.
Changed
- Every byte sequence acc hashes or signs is the RFC 8785 (JCS) serialization of the normalized
value (spec §8.2), through one module (src/canonical). The trailing newline that was part of
every preimage is gone, so finding identifiers,generated.source_digestand thesha256
subject digest change. Every finding, assessment and verdict across the fixture set is the same. - JSON outputs (
--format json,in-toto,sarif, andexport) are written as exactly the JCS
bytes, with no trailing newline, so the SHA-256 of a manifest file is its digest. JSON Lines
keep one newline after each Statement as a separator. - Manifests are version
0.3, the predicate type is
https://noru.tech/spec/ai-change-provenance/v0.3, and exports and resolved policies are
written as0.3. Exports and policies of0.1and0.2remain valid input.
Added
legacy_idson findings: the identifier the same finding had under 0.2, kept for one minor
version.acc checkcarries a disposition over by either identifier.- I-JSON input constraints (spec §8.2), enforced by
evaluate,validate,check, policy
loading and attestation loading: ACV005 non-integer number, ACV006 integer outside
±(2^53 − 1), ACV007 unpaired surrogate, ACV008 duplicate member name, ACV009 nesting deeper
than 128 (rejected without parsing further). acc validatestill accepts ACP 0.2 manifests andv0.2Statements, including attestations
made by acc 0.4.0: it recomputes their digests with the legacy canonicalization and says so.acc evaluate --conformance-json VECTORprints the single-line result object of the
evaluator conformance contract (verdict, failing codes, assessments, manifest digest) and exits
0 evaluated, 3 invalid, 4 incomplete.- The evaluator conformance corpus (
conformance/, spec §9): 32 accept, 18 reject and 4
incomplete vectors under an external-verifier contract, a standard-library Python harness
(run.py) that writesconformance-report.json, a GitHub Action (conformance/action.yml),
and a generatedCORPUS-DIGESTS.txtthatconformance-release.ymlsigns at each tag. Every
reject vector is one mutation of an accept vector. CI runs the corpus againstaccand against
builds with one rule, or the serialization, deliberately broken, and requires those to fail. - ACV010 for input that does not conform to its schema; spec §6.6 lists every validation code.
- CI recomputes the goldens' digests with an independent RFC 8785 implementation in Python
(rfc8785), without acc's code.
Install agent-change-control 0.5.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.5.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control