Skip to content

Releases: omkhar/workcell

v1.0.2

Choose a tag to compare

@github-actions github-actions released this 05 Aug 04:44
Immutable release. Only release title and notes can be modified.
v1.0.2
b931106

What's Changed

Full Changelog: v1.0.1...v1.0.2

v1.0.0-rc.2

Choose a tag to compare

@github-actions github-actions released this 13 Jul 10:57
Immutable release. Only release title and notes can be modified.
v1.0.0-rc.2
12046e9

What's Changed

  • Harden security pins and direct mount staging by @omkhar in #351
  • Refresh pinned upstreams by @omkhar in #352
  • ^F Add Antigravity fail-closed scaffold by @omkhar in #353
  • Fix Colima staging cache mounts by @omkhar in #354
  • Add Copilot release pin verifier by @omkhar in #355
  • Keep pin hygiene green when Rust Docker tag lags by @omkhar in #357
  • chore: bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group across 1 directory by @dependabot[bot] in #356
  • Add host auth-state foundations by @omkhar in #358
  • Harden Copilot release verification modes by @omkhar in #359
  • Add Copilot auth policy metadata groundwork by @omkhar in #360
  • ^F Add certified adapter PR shape override by @omkhar in #361
  • Add GitHub Copilot Tier 1 adapter by @omkhar in #362
  • Add 1.0 program: roadmap improvement tracks and implementation plan by @omkhar in #363
  • Add support-tier docs and support-matrix field-parity check (E3) by @omkhar in #364
  • Add markdown link and orphan CI check (E4) by @omkhar in #365
  • Add OWASP Agentic Top-10 control mapping (A7) by @omkhar in #366
  • Document the Rust/Go/shell language-boundary doctrine (D1) by @omkhar in #367
  • Add artifact retention policy and drift check (B5) by @omkhar in #368
  • Add mutation-score baseline gate (B3 core) by @omkhar in #369
  • Add reviewed GitHub Actions allowlist (B4 core) by @omkhar in #370
  • Centralize CI tool pins into reviewed policy (B4b) by @omkhar in #371
  • Add scheduled mutation-score CI lane (B3b) by @omkhar in #372
  • Document and enforce unsafe-code safety invariants (A4) by @omkhar in #373
  • Add SLSA v1.0 Build-track gap analysis to the provenance doc (B1) by @omkhar in #374
  • Stability contracts: unify the exit-code contract and document it (D8) by @omkhar in #375
  • Add a standards watchlist (F3) by @omkhar in #376
  • Public contract inventory + drift check (G1 part 1) by @omkhar in #377
  • Add maintained architecture diagrams (E2) by @omkhar in #378
  • Add Go fuzzing targets and a scheduled fuzz lane (A3) by @omkhar in #379
  • Restructure README into tiered entry points (E1) by @omkhar in #380
  • Add operator egress policy depth: [network] allowlist surface (A1) by @omkhar in #381
  • ^F Treat an empty egress allowlist as deny-all (A1 follow-up) by @omkhar in #382
  • ^F Add Rust cargo-fuzz targets for exec-guard classifiers (A3) by @omkhar in #383
  • ^F Add exec-guard syscall-shim performance baselines (C5) by @omkhar in #384
  • ^F Add CI/CD threat model (B9) by @omkhar in #385
  • ^R CI efficiency and reliability program (B8) by @omkhar in #386
  • ^f Support-bundle redaction core (G2, 1/3) by @omkhar in #388
  • ^F Support-bundle collector + leak-proof + golden (G2, 2/3) by @omkhar in #389
  • ^F workcell support-bundle command + audit hardening (G2, 3/3) by @omkhar in #390
  • ^B Use snapshot-cloudflare.debian.org CDN mirror (origin fallback) to end mirror-halting CI by @omkhar in #392
  • ^D Document injection-policy schema + doc/parser drift check (E5) by @omkhar in #391
  • ^D Contributor runbook depth: adapter READMEs + worked examples (E7) by @omkhar in #387
  • ^f C2 session-start latency benchmark harness (locally-validatable core) by @omkhar in #393
  • ^R D4: extract host-detection into scripts/lib/launcher/host-detect.sh + launcher-contract.md by @omkhar in #394
  • ^R D4: extract trusted host-command execution into scripts/lib/launcher/host-exec.sh by @omkhar in #395
  • ^R D4: extract Go/Colima host-utility wrappers into scripts/lib/launcher/go-hostutil.sh by @omkhar in #396
  • ^d D4: complete launcher-contract.md with required-tools/env/exit-codes/test-flags reference by @omkhar in #397
  • ^R D3: migrate git-config-blocklist parity check from verify-invariants.sh to Go by @omkhar in #398
  • ^R D3: migrate scripts/workcell hardening invariants from verify-invariants.sh to Go by @omkhar in #399
  • ^R D3: migrate scripts/workcell config-safety checks from verify-invariants.sh to Go by @omkhar in #400
  • ^R D3: migrate scripts/workcell runtime/gc invariants from verify-invariants.sh to Go by @omkhar in #401
  • ^R D3: migrate scripts/workcell managed-profile staging invariants from verify-invariants.sh to Go by @omkhar in #402
  • ^R D3: migrate scripts/workcell bootstrap egress-endpoint invariants from verify-invariants.sh to Go by @omkhar in #403
  • ^R D3: migrate scripts/workcell bootstrap-audit-metadata invariants from verify-invariants.sh to Go by @omkhar in #404
  • ^R D3: migrate scripts/workcell git-index/shadow function-block invariants to Go by @omkhar in #405
  • ^R D3: migrate scripts/workcell publish-pr/shadow-mount invariants to Go by @omkhar in #406
  • ^R D3: migrate scripts/workcell shadow-enumeration + egress-ip6tables invariants to Go by @omkhar in #407
  • ^R D3: migrate home-seeding + provider-wrapper env-scrub invariants to Go (57 checks) by @omkhar in #408
  • ^R D3: migrate copilot prefix-scrub + token-handoff invariants to Go (29 checks) by @omkhar in #409
  • ^R D3: migrate copilot/docker-run token-handoff invariants to Go (25 checks) by @omkhar in #410
  • ^R D3: migrate provider-launcher-authority invariants to Go (30 checks) by @omkhar in #411
  • ^R D3: migrate copilot-policy provider-wrapper invariants to Go (22 checks) by @omkhar in #412
  • ^R D3: migrate copilot unsafe-flag invariants to Go (31 checks, +present-in-any-file kind) by @omkhar in #413
  • ^R D3: migrate copilot upstream-release-verify invariants to Go (24 checks) by @omkhar in #414
  • ^R D3: migrate adapter-rule/guard-bash invariants to Go (18 checks, +count-at-least kind) by @omkhar in #415
  • ^R D3: migrate inspect/assurance grep-loop invariants to Go (25 checks) by @omkhar in #416
  • ^R D3: migrate validator writable-state isolation invariants to Go (23 checks) by @omkhar in #417
  • ^R D3: migrate hostutil/entrypoint/colima-egress rg invariants to Go (21 checks) by @omkhar in #418
  • ^R D3: migrate dockerfile-pin rg invariants to Go (30 checks) by @omkhar in #419
  • ^R D3: migrate validator-env/dispatch loop invariants to Go (13 checks) by @omkhar in #420
  • ^R D3: migrate nested caller×required validator-isolation invariants to Go (50 checks) by @omkhar in #421
  • ^R D3: migrate fn-block/go-fn-block/git-env invariants to Go (8 checks, +go-function-block kind) by @omkhar in #422
  • ^R D3: migrate 4 scattered simple-check clusters to Go (20 checks, 4 subcommands) by @omkhar in #423
  • ^R D3: final simple-check sweep to Go (16 checks, 6 subcommands + orphan-helper cleanup) by @omkhar in #424
  • ^R D3: add dir-exists/executable/fn-block-regex-absent kinds + migrate 3 checks to Go by @omkhar in #425
  • ^R D3: migrate static jq -e adapter-settings invariants to Go (kindJSONExprEval, 4 checks) by @omkhar in #426
  • ^d D3: refresh workcellhardening package doc to the current migration state by @omkhar in #427
  • ^d Fix orphaned docs/session-startup-benchmarks.md (docs CI green) by @omkhar in #428
  • ^r D3: backfill real-repo assertions for the early workcellhardening groups (tests only) by @omkhar in https://gi...
Read more

v0.11.2

Choose a tag to compare

@github-actions github-actions released this 15 Jun 19:29
Immutable release. Only release title and notes can be modified.
v0.11.2
de463d1

What's Changed

  • Release v0.11.2 — repoint mutation harness anchors by @omkhar in #349

Full Changelog: v0.11.1...v0.11.2

v0.10.7

Choose a tag to compare

@github-actions github-actions released this 30 May 14:57
Immutable release. Only release title and notes can be modified.
v0.10.7
113d97d

What's Changed

  • Add Copilot CLI Tier 1 parity roadmap by @omkhar in #264
  • Polish Copilot CLI roadmap docs after review by @omkhar in #266
  • ^B Fix four silent error-swallow correctness bugs (sethify findings) by @omkhar in #267
  • ^B+^F Security hygiene: TOCTOU fixes, O_NOFOLLOW, GOOS gating, curl caps, mutable banner (sethify findings) by @omkhar in #269
  • ^R Dead code & idiom cleanup: runLauncherCompat, git-launcher.rs, stdlib swaps (sethify findings) by @omkhar in #270
  • ^R Refactor: adapter table collapse + authpolicy flag-parser dedup (sethify findings) by @omkhar in #271
  • ^D Docs/naming fixes: --ui, mode map, Copilot status, package docs (sethify findings) by @omkhar in #272
  • ^F+^R CI/CD hygiene: validator cache scope + strict bash + PR pin gate (sethify findings) by @omkhar in #268
  • ^F Unify git-config blocklist via policy/ TOML + parity check (closes #275) by @omkhar in #277
  • ^R Collapse metadatautil sub-packages into parent (closes #276) by @omkhar in #278
  • ^R Split god-files: extract Path, staging.go, bootstrap.go (sethify followup) by @omkhar in #280
  • ^R Extract shared PolicySource type into internal/injectionpolicy (closes #274) by @omkhar in #279
  • ^B Revert defaults block from scorecard.yml (main-CI fix) by @omkhar in #281
  • chore: bump the github-actions group across 1 directory with 3 updates by @dependabot[bot] in #265
  • chore: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/markdownlint in the npm_and_yarn group across 1 directory by @dependabot[bot] in #263
  • Fix upstream refresh and bootstrap network resilience by @omkhar in #283
  • Keep Debian refreshes bootstrap-buildable by @omkhar in #284
  • Harden runtime build retry recovery by @omkhar in #285
  • Preserve refresh publication validation by @omkhar in #286
  • Refresh pinned upstreams by @omkhar in #287
  • Harden GitHub API redirect authentication by @omkhar in #288
  • Add repository readiness gate by @omkhar in #289
  • Refresh pinned upstreams by @omkhar in #290
  • Remove dead code: unused exit1, ptyNameBufferSize, redundant loop copy by @omkhar in #291
  • Dedup metadatautil/injection helpers; drop unused param by @omkhar in #292
  • providerid: derive IsValid from AllProviders; single package doc by @omkhar in #293
  • Dedup config-home path; reuse scenarios key helpers by @omkhar in #294
  • hostutil: extract parseSessionRootsSingle for single-id session helpers by @omkhar in #295
  • publishpr: extract resolveAgainstWorkspace from resolve helpers by @omkhar in #297
  • Remove dead bash helpers (shasum precondition, workcell_die, reject_if_protected_provider_path) by @omkhar in #296
  • public-node-guard: compute isProtectedProviderFile once in maybeBlock by @omkhar in #298
  • check-repo-readiness: fetch tracker issue list once by @omkhar in #299
  • trusted-docker-client: dedup duplicated registry CA blocks by @omkhar in #300
  • runtime wrappers: hoist shared env pin/sanitize into runtime-user.sh by @omkhar in #301
  • execveat: reuse classify_loader_target / loader_targets_mutable_native_exec by @omkhar in #302
  • colima-timeout harness: extract assert_contains for forwarded-arg checks by @omkhar in #303
  • execveat: rustfmt the loader_targets_mutable_native_exec assignment by @omkhar in #304

Full Changelog: v0.10.6...v0.10.7

v0.10.6

Choose a tag to compare

@github-actions github-actions released this 18 May 15:50
Immutable release. Only release title and notes can be modified.
v0.10.6
23136a5

What's Changed

  • Fix upstream refresh and workflow gates by @omkhar in #170
  • chore: bump github/codeql-action from 4.35.1 to 4.35.2 in the github-actions group across 1 directory by @dependabot[bot] in #169
  • Fix publish-pr signed range enforcement by @omkhar in #171
  • Refresh pinned upstreams by @omkhar in #172
  • Refresh pinned upstreams by @omkhar in #174
  • Hash-pin zizmor workflow install by @omkhar in #175
  • Record Phase 10-12 roadmap gates by @omkhar in #176
  • Fix provider-bump check status capture in update-upstream-pins.sh by @omkhar in #177
  • Gate release.yml preflight on main checks being green by @omkhar in #178
  • Add timeout-minutes to every workflow job by @omkhar in #179
  • Bound HTTP timeout, request context, and response body in provider_bumps fetches by @omkhar in #180
  • Use cmd.Output() not CombinedOutput() for gh api ruleset detail by @omkhar in #181
  • Centralize sanitized-entrypoint preamble across 10 host-side scripts by @omkhar in #182
  • Modernize 58 sort.Strings call sites to slices.Sort by @omkhar in #183
  • Fix correctness cluster in internal/hostutil/launcher.go (6 bug fixes) by @omkhar in #184
  • Fix small-bug cluster: scenarios, metadatautil, scripts/workcell trap, mutation runner by @omkhar in #185
  • Install full validator toolchain via install-dev-tools.sh; align release.yml zizmor to 1.24.1 by @omkhar in #187
  • Rename cmd/workcell-treecompare to cmd/workcell-tree-compare by @omkhar in #189
  • Link closed-finding evidence from SECURITY.md by @omkhar in #188
  • Add control-plane lockstep invariant under verify/invariants/ by @omkhar in #190
  • Introduce internal/providerid constants and migrate 71 raw-string sites by @omkhar in #191
  • Docs consistency pass: man, README, codex adapter README, CONTRIBUTING, dead markdownlint rule, auth unset by @omkhar in #186
  • Small CI/CD + 🔵 cleanup cluster: ghcr login, cp -RP, map sort, EIO, max-filesize, pin-hygiene comment by @omkhar in #193
  • Extract internal/tomlsubset canonical parser and dedupe stripComment across 5 packages by @omkhar in #192
  • Centralize per-provider tables in internal/adapters/{p}/ by @omkhar in #194
  • Delete tests and doc.go for dormant internal/policybundle (1 of 2 deletion PRs) by @omkhar in #198
  • Add dated --ack-breakglass=YYYY-MM-DD and --ack-arbitrary-command=YYYY-MM-DD forms by @omkhar in #195
  • Make release attestations fail-closed with WORKCELL_RELEASE_NO_ATTEST opt-out by @omkhar in #196
  • Move forbidden host-path enumeration into policy/forbidden-host-paths.toml by @omkhar in #197
  • Shrink dormant internal/policybundle/policy_bundle.go to stub vars + PolicySource (1 of 2) by @omkhar in #199
  • Tidy mutation runner with goCmd helper, rename resolvePathLikePython, drop Python-mirror comments by @omkhar in #200
  • Extract GitHub-release helpers into internal/host/release (1 of hostutil split series) by @omkhar in #201
  • Delete dormant internal/policybundle (final step of D6) by @omkhar in #202
  • Extract support-matrix into internal/host/supportmatrix (2 of hostutil split series) by @omkhar in #203
  • Extract sessions package into internal/host/sessions (3 of hostutil split series) by @omkhar in #204
  • ^R Extract Colima + profile-lock cluster into internal/host/launcher by @omkhar in #205
  • ^R Extract host-state/mounts/audit cluster into internal/host/hoststate by @omkhar in #206
  • ^R Finish hostutil split: move remaining helpers into internal/host/launcher, delete internal/hostutil by @omkhar in #207
  • ^R Extract workflow validators into internal/metadatautil/workflows by @omkhar in #208
  • ^R Extract hosted-controls policy helpers into internal/metadatautil/hostedcontrols by @omkhar in #209
  • ^R Move VerifyGitHubHostedControls into internal/metadatautil/hostedcontrols by @omkhar in #210
  • ^R Extract CheckPinnedInputs into internal/metadatautil/pinnedinputs by @omkhar in #211
  • ^A Validate AppArmor/SELinux in daemon and post-launch HostConfig.SecurityOpt by @omkhar in #212
  • ^R Collapse cmd/workcell-hostutil launcher switch into a registry table by @omkhar in #213
  • ^R Convert cmd/workcell-metadatautil dispatch to a registry pattern by @omkhar in #214
  • ^R Move install-deps mock binaries out of verify-invariants.sh into harnesses/ by @omkhar in #215
  • ^R Bootstrap internal/sessionctl: move session_usage help text to Go by @omkhar in #216
  • ^R Move session_timeline_main into internal/sessionctl/TimelineMain by @omkhar in #219
  • ^R Move process/colima harness bodies into verify/invariants/harnesses/process-colima/ by @omkhar in #220
  • ^R Move git-probe heredocs + gemini-auth-selection harness into verify/invariants/harnesses/ by @omkhar in #221
  • ^R Translate session_logs_main into internal/sessionctl/LogsMain by @omkhar in #222
  • ^R Extend internal/tomlsubset with shared tokenizer and AST by @omkhar in #223
  • ^R Extract auth_usage and policy_usage heredocs into internal/authpolicy by @omkhar in #224
  • ^R Extract publish_pr_usage heredoc into internal/publishpr by @omkhar in #225
  • ^R Migrate authpolicy and authresolve to shared tomlsubset by @omkhar in #228
  • ^R Translate auth_main into internal/authpolicy/AuthMain by @omkhar in #230
  • ^R Translate session_attach_main into internal/sessionctl/AttachMain by @omkhar in #227
  • ^R Translate publish_pr_main validators into internal/publishpr (24.2a) by @omkhar in #231
  • ^R Translate policy_main into internal/authpolicy/PolicyMain by @omkhar in #229
  • ^R Translate colima helpers into internal/host/launcher by @omkhar in #226
  • ^R Migrate injection to shared tomlsubset (closes Section F) by @omkhar in #234
  • ^R Translate profile path helpers into Go by @omkhar in #235
  • ^R Translate prepare_injection_bundle/direct_mounts into internal/injection by @omkhar in #236
  • ^R Translate docker client + process helpers into Go by @omkhar in #237
  • ^R Translate session_stop_main into internal/sessionctl/StopMain by @omkhar in #238
  • ^R Translate session_send_main into internal/sessionctl/SendMain by @omkhar in #232
  • ^R Wire publish_pr_main shim through publishpr.PublishPRMain (24.2b) by @omkhar in #233
  • ^R Translate session_delete_main into internal/sessionctl/DeleteMain (22.6) by @omkhar in #239
  • ^R Translate session_monitor + session_main dispatcher (22.7) by @omkhar in #240
  • ^R Collapse cmd binaries: 7 thin cmds into 3 umbrellas (26) by @omkhar in #241
  • ^B Fix sethify blockers + cliexit foundation (fix-1a) by @omkhar in #242
  • ^R Sessionctl dispatch rename + shim dedup (fix-1b) by @omkhar in #243
  • ^R Quality cleanup + pathutil/stateroot extraction (fix-2) by @omkhar in #244
  • ^R Extract internal/shellproto for bash↔Go KEY=VALUE protocol (fix-3) by @omkhar in #245
  • ^R Cmd docs + naming polish (fix-4) by @omkhar in #246
  • ^B Sethify round-2 critical: red + near-red + cliexit completion (fix-5) by @omkhar in #247
  • ^R Sethify round-2 architecture closures (fix-6) by @omkhar in #248
  • ^R Sethify round-2 docs + polish + Q4 (fix-7) by @omkhar in #249
  • ^B Sethify round-3 critical follow-up (fix-8)...
Read more

v0.10.5

Choose a tag to compare

@github-actions github-actions released this 25 Apr 21:40
Immutable release. Only release title and notes can be modified.
v0.10.5
700de9d

What's Changed

Full Changelog: v0.10.4...v0.10.5

v0.10.3

Choose a tag to compare

@github-actions github-actions released this 18 Apr 04:51
Immutable release. Only release title and notes can be modified.
v0.10.3
678efd9

What's Changed

Full Changelog: v0.10.2...v0.10.3

v0.10.2

Choose a tag to compare

@github-actions github-actions released this 17 Apr 21:20
Immutable release. Only release title and notes can be modified.
v0.10.2
3332c52

What's Changed

Full Changelog: v0.10.1...v0.10.2

v0.10.1

Choose a tag to compare

@github-actions github-actions released this 17 Apr 19:48
Immutable release. Only release title and notes can be modified.
v0.10.1
eca0064

What's Changed

Full Changelog: v0.10.0...v0.10.1

v0.10.0

Choose a tag to compare

@github-actions github-actions released this 17 Apr 18:23
v0.10.0
83ab4b9

What's Changed

  • docs: formalize release and async review policy by @omkhar in #100
  • Document release review workflow and refresh roadmap by @omkhar in #101
  • [codex] Harden managed runtime and validation boundaries by @omkhar in #102
  • [codex] Remove remote heavy validation lane by @omkhar in #103
  • [codex] Align hosted controls with current review posture by @omkhar in #105
  • chore: bump docker/build-push-action from 7.0.0 to 7.1.0 in the github-actions group by @dependabot[bot] in #104
  • Align docs with current session and rollout state by @omkhar in #106
  • Enforce traceability for release-facing docs by @omkhar in #108
  • Repair mainline validate-repo baseline by @omkhar in #110
  • Refresh release pins and cap Claude at 2.1.104 by @omkhar in #109
  • Fix session runtime control and resize regressions by @omkhar in #107
  • Refresh release inputs with a Claude 2.1.104 holdback by @omkhar in #112
  • Add recurring release readiness sweeps by @omkhar in #113
  • Harden smoke host-path handling against symlink traversal by @omkhar in #111
  • Harden runtime control-plane boundaries by @omkhar in #114
  • Align hosted-controls policy with review-gated main by @omkhar in #115
  • Release v0.10.0 by @omkhar in #116

Full Changelog: v0.9.3...v0.10.0