Skip to content

0.5.3 - 2026-09-30

Choose a tag to compare

@github-actions github-actions released this 01 Oct 05:46
d722be9

Release Notes

Distribution, documentation and CI only; no change to the tool's behaviour.

Added

  • A CycloneDX SBOM (agent-change-control.cdx.xml) attached to every release, generated by
    cargo-cyclonedx through dist (cargo-cyclonedx = true; release.yml regenerated with dist
    0.33.0 and its action pins re-applied).
  • Every release publishes the crate to crates.io: release.yml calls publish-crate.yml as a
    dist custom publish job after the GitHub Release is up. It uses Trusted Publishing (a
    short-lived token from rust-lang/crates-io-auth-action, no stored secret), skips a version
    that is already published, and can be run by hand with a tag as a fallback.
  • scorecard.yml: OpenSSF Scorecard analysis, published to scorecard.dev, with a README badge.
  • KNOWN-LIMITATIONS.md, collecting what acc does not do and cannot know.
  • A feature request issue form, a VHS script for the README recording (docs/demo.tape), and
    weekly grouped Dependabot updates for Cargo dependencies.

Changed

  • The crate is published on crates.io as agent-change-control: README shows its badge and the
    cargo binstall / cargo install lines again. Also in the README: a "Verify
    before you run" section with the exact attestation and checksum commands; a Trust section;
    sections reordered (install first, then quick start, what it does and what it is not).
  • Cargo.toml: a one-sentence description, and in-toto and provenance keywords in place of
    github and cli.
  • SECURITY.md links GitHub private vulnerability reporting directly and gives the full
    verification commands.

Install agent-change-control 0.5.3

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.5.3/agent-change-control-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/acc

Download agent-change-control 0.5.3

File Platform Checksum
agent-change-control-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
agent-change-control-x86_64-apple-darwin.tar.xz Intel macOS checksum
agent-change-control-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
agent-change-control-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-control

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control