Immutable
release. Only release title and notes can be modified.
Release Notes
Added
codeql.yml: CodeQL static analysis of the Rust, Python and workflow code on every pull request,
on main and weekly; results go to code scanning.- A stable documentation page for every rule (
docs/rules/ACC001.md…), every validation code
(docs/rules/ACV001.mdtoACV010.md) and the exit codes (docs/exit-codes.md), with an index
atdocs/rules/README.md. Each rule page gives the rule in one sentence, why it matters, every
outcome with its exact reason text, the documented control mapping, a failing and a passing
example on a real fixture, how to fix it and how to record a disposition. - SARIF rule descriptors carry
helpUri, linking each rule to its page. The base URL is one
constant (DOCS_BASE_URL), so the pages can move to a docs site later. - Error messages that name a validation code end with
(see <url>), the code's page. Only the
human-readable stderr line changes; JSON, YAML, SARIF results, manifests and the conformance
result line are unchanged. llms.txtat the repository root (llms.txt convention): whataccis, install commands and
links to the most important pages.docs/openssf-best-practices.md: prepared answers for the OpenSSF Best Practices passing level.- Consistent CLI flags.
--format textis an alias oftablewherevertableis accepted, with
identical bytes. A global-v/--verboseprints extra diagnostics on stderr (resolved policy,
format and destination, counts, whether a token is used); stdout is unchanged. A global
--no-color, and a non-emptyNO_COLOR, switch off color in clap's help and usage errors;
acc's own output was and stays uncolored. acc validate --format text|jsonand--output FILE. JSON is a new machine output: one result
object withvalid,message, andcodeandhelp_uriwhen a validation code applies (README,
"Output formats and exit codes"). Text, the default, is unchanged.acc completions SHELL --output FILEandacc manpage --output FILEwrite to a file.- Errors with a fix and a docs link. The common failures print two more stderr lines after
error: …:help: …(what to do) andsee: <url>(the section ofdocs/exit-codes.md, or the
policy page): a missing or rejected token (exit 5), a rate limit, a forbidden or missing
repository and transport failures (exit 6; a 403 with an exhausted rate limit is told apart from a
permission problem), a missing--repo/GITHUB_REPOSITORY, a bad--since/--until/--as-of
or a reversed window (exit 2), and an invalid policy file (exit 3). An incomplete collection
(exit 4) printswarning: collection incomplete: <reason>with the same lines, unless-q.
Messages, exit codes and every machine-readable output are unchanged.Failuregains optional
hintandseefields. - Zero-config collection:
acc scan(andexport) works with no arguments in a GitHub clone.
GitHub is the default forge (acc scan acme/apiisacc scan github acme/api);OWNER/REPO
defaults toGITHUB_REPOSITORY, else the github.comoriginremote (https, ssh and
git@github.com:forms), whichprnow also falls back to; a missing--untilis now and a
missing--sinceis 30 days before the end, in UTC. The resolved repository and window are
printed on stderr and the window is recorded in the output exactly as if passed, so evaluation
stays deterministic. Only the collecting commands read the clock (ACC_NOWreplaces it in
tests). acc doctor [--online] [--format text|json]: the version, whetherGITHUB_TOKEN/GH_TOKENis
set (never its value), whether the default policy file parses, and the repositoryscanwould
detect.--onlineadds GET-only checks: the token and rate limit (GET /rate_limit) and the
latest release, to report a neweracc; this is the only update check and it never runs on its
own. Exit 0 when healthy, 2 when a check failed. The JSON report is a new machine output
(README).- Release archives carry shell completions (
completions/acc.bash,_acc,acc.fish) and man
pages (man/acc.1and one per subcommand), through cargo-dist'sinclude; the Homebrew formula
installs them (bash_completion,zsh_completion,fish_completion,man1). They are
committed and a test keeps them identical to whataccgenerates. The formula step is a fifth
documented hand edit ofrelease.yml(CONTRIBUTING). ACC_GITHUB_API_URL, testing only: points the binary at the loopback replay server. Only
http://127.0.0.1:PORT/http://localhost:PORTwithout a token is accepted.
Changed
- README: four headings are now the questions people ask ("How do I enforce separation of duties
for AI coding agents?", "What does acc not do?", "How does acc decide whether a change was
independently approved?", "Which rules does acc check?"); the old anchors still resolve. Each
rule in the Rules table links to its page. tests/metadata.rschecks that every rule and validation code has a page and that the
documented action pins name the crate version.
Install agent-change-control 0.6.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.6.0/agent-change-control-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/accDownload agent-change-control 0.6.0
| File | Platform | Checksum |
|---|---|---|
| agent-change-control-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| agent-change-control-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| agent-change-control-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| agent-change-control-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-controlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control