0.5.3 - 2026-09-30
Release Notes
Distribution, documentation and CI only; no change to the tool's behaviour.
Added
- A CycloneDX SBOM (
agent-change-control.cdx.xml) attached to every release, generated by
cargo-cyclonedxthrough dist (cargo-cyclonedx = true;release.ymlregenerated with dist
0.33.0 and its action pins re-applied). - Every release publishes the crate to crates.io:
release.ymlcallspublish-crate.ymlas a
dist custom publish job after the GitHub Release is up. It uses Trusted Publishing (a
short-lived token fromrust-lang/crates-io-auth-action, no stored secret), skips a version
that is already published, and can be run by hand with a tag as a fallback. scorecard.yml: OpenSSF Scorecard analysis, published to scorecard.dev, with a README badge.KNOWN-LIMITATIONS.md, collecting whataccdoes not do and cannot know.- A feature request issue form, a VHS script for the README recording (
docs/demo.tape), and
weekly grouped Dependabot updates for Cargo dependencies.
Changed
- The crate is published on crates.io as
agent-change-control: README shows its badge and the
cargo binstall/cargo installlines again. Also in the README: a "Verify
before you run" section with the exact attestation and checksum commands; a Trust section;
sections reordered (install first, then quick start, what it does and what it is not). Cargo.toml: a one-sentence description, andin-totoandprovenancekeywords in place of
githubandcli.SECURITY.mdlinks GitHub private vulnerability reporting directly and gives the full
verification commands.
Install agent-change-control 0.5.3
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.3/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.5.3
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control