Skip to content

0.6.0 - 2026-10-01

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 10:38
Immutable release. Only release title and notes can be modified.
0c140ee

Release Notes

Added

  • codeql.yml: CodeQL static analysis of the Rust, Python and workflow code on every pull request,
    on main and weekly; results go to code scanning.
  • A stable documentation page for every rule (docs/rules/ACC001.md …), every validation code
    (docs/rules/ACV001.md to ACV010.md) and the exit codes (docs/exit-codes.md), with an index
    at docs/rules/README.md. Each rule page gives the rule in one sentence, why it matters, every
    outcome with its exact reason text, the documented control mapping, a failing and a passing
    example on a real fixture, how to fix it and how to record a disposition.
  • SARIF rule descriptors carry helpUri, linking each rule to its page. The base URL is one
    constant (DOCS_BASE_URL), so the pages can move to a docs site later.
  • Error messages that name a validation code end with (see <url>), the code's page. Only the
    human-readable stderr line changes; JSON, YAML, SARIF results, manifests and the conformance
    result line are unchanged.
  • llms.txt at the repository root (llms.txt convention): what acc is, install commands and
    links to the most important pages.
  • docs/openssf-best-practices.md: prepared answers for the OpenSSF Best Practices passing level.
  • Consistent CLI flags. --format text is an alias of table wherever table is accepted, with
    identical bytes. A global -v/--verbose prints extra diagnostics on stderr (resolved policy,
    format and destination, counts, whether a token is used); stdout is unchanged. A global
    --no-color, and a non-empty NO_COLOR, switch off color in clap's help and usage errors;
    acc's own output was and stays uncolored.
  • acc validate --format text|json and --output FILE. JSON is a new machine output: one result
    object with valid, message, and code and help_uri when a validation code applies (README,
    "Output formats and exit codes"). Text, the default, is unchanged.
  • acc completions SHELL --output FILE and acc manpage --output FILE write to a file.
  • Errors with a fix and a docs link. The common failures print two more stderr lines after
    error: …: help: … (what to do) and see: <url> (the section of docs/exit-codes.md, or the
    policy page): a missing or rejected token (exit 5), a rate limit, a forbidden or missing
    repository and transport failures (exit 6; a 403 with an exhausted rate limit is told apart from a
    permission problem), a missing --repo/GITHUB_REPOSITORY, a bad --since/--until/--as-of
    or a reversed window (exit 2), and an invalid policy file (exit 3). An incomplete collection
    (exit 4) prints warning: collection incomplete: <reason> with the same lines, unless -q.
    Messages, exit codes and every machine-readable output are unchanged. Failure gains optional
    hint and see fields.
  • Zero-config collection: acc scan (and export) works with no arguments in a GitHub clone.
    GitHub is the default forge (acc scan acme/api is acc scan github acme/api); OWNER/REPO
    defaults to GITHUB_REPOSITORY, else the github.com origin remote (https, ssh and
    git@github.com: forms), which pr now also falls back to; a missing --until is now and a
    missing --since is 30 days before the end, in UTC. The resolved repository and window are
    printed on stderr and the window is recorded in the output exactly as if passed, so evaluation
    stays deterministic. Only the collecting commands read the clock (ACC_NOW replaces it in
    tests).
  • acc doctor [--online] [--format text|json]: the version, whether GITHUB_TOKEN/GH_TOKEN is
    set (never its value), whether the default policy file parses, and the repository scan would
    detect. --online adds GET-only checks: the token and rate limit (GET /rate_limit) and the
    latest release, to report a newer acc; this is the only update check and it never runs on its
    own. Exit 0 when healthy, 2 when a check failed. The JSON report is a new machine output
    (README).
  • Release archives carry shell completions (completions/acc.bash, _acc, acc.fish) and man
    pages (man/acc.1 and one per subcommand), through cargo-dist's include; the Homebrew formula
    installs them (bash_completion, zsh_completion, fish_completion, man1). They are
    committed and a test keeps them identical to what acc generates. The formula step is a fifth
    documented hand edit of release.yml (CONTRIBUTING).
  • ACC_GITHUB_API_URL, testing only: points the binary at the loopback replay server. Only
    http://127.0.0.1:PORT/http://localhost:PORT without a token is accepted.

Changed

  • README: four headings are now the questions people ask ("How do I enforce separation of duties
    for AI coding agents?", "What does acc not do?", "How does acc decide whether a change was
    independently approved?", "Which rules does acc check?"); the old anchors still resolve. Each
    rule in the Rules table links to its page.
  • tests/metadata.rs checks that every rule and validation code has a page and that the
    documented action pins name the crate version.

Install agent-change-control 0.6.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/agent-change-control/releases/download/v0.6.0/agent-change-control-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/acc

Download agent-change-control 0.6.0

File Platform Checksum
agent-change-control-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
agent-change-control-x86_64-apple-darwin.tar.xz Intel macOS checksum
agent-change-control-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
agent-change-control-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/agent-change-control

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/agent-change-control