Skip to content

0.5.2 - 2026-09-29

Choose a tag to compare

@github-actions github-actions released this 29 Sep 18:49
1fad4bb

Release Notes

Conformance suite revision 2 in a signed release. No change to the rules or the output beyond
the recorded tool version.

Added

  • Conformance suite revision 2: three vectors for the opt-in instructions independence
    dimension (independent, dependent, unknown); 35 accept, 18 reject and 4 incomplete vectors.
  • Tests that a review attestation naming another agent than a verified account mapping, and a
    human reviewer's review attestation naming an operator or instructions, are errors.
  • The Zenodo concept DOI (10.5281/zenodo.23042500) in CITATION.cff, a DOI badge and a Citing
    section in the README.

Changed

  • The self-check and attest workflows run the published 0.5.1.
  • The README's spec badge and prose name AI Change Provenance 0.3; tests/metadata.rs now
    requires every "AI Change Provenance X.Y" in the README and docs to name the current version,
    and the DOI to be the same everywhere.
  • Specification §9 no longer names a single conformance suite revision (0.3 revision 3):
    revision 1 was published at v0.5.0, and later revisions only add vectors or correct expected
    results.

Install agent-change-control 0.5.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.2/agent-change-control-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/acc

Download agent-change-control 0.5.2

File Platform Checksum
agent-change-control-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
agent-change-control-x86_64-apple-darwin.tar.xz Intel macOS checksum
agent-change-control-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
agent-change-control-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-control

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control