Releases: omkhar/workcell
Releases · omkhar/workcell
Release list
v1.0.2
Immutable
release. Only release title and notes can be modified.
v1.0.0-rc.2
Immutable
release. Only release title and notes can be modified.
What's Changed
- Harden security pins and direct mount staging by @omkhar in #351
- Refresh pinned upstreams by @omkhar in #352
- ^F Add Antigravity fail-closed scaffold by @omkhar in #353
- Fix Colima staging cache mounts by @omkhar in #354
- Add Copilot release pin verifier by @omkhar in #355
- Keep pin hygiene green when Rust Docker tag lags by @omkhar in #357
- chore: bump actions/checkout from 6.0.3 to 7.0.0 in the github-actions group across 1 directory by @dependabot[bot] in #356
- Add host auth-state foundations by @omkhar in #358
- Harden Copilot release verification modes by @omkhar in #359
- Add Copilot auth policy metadata groundwork by @omkhar in #360
- ^F Add certified adapter PR shape override by @omkhar in #361
- Add GitHub Copilot Tier 1 adapter by @omkhar in #362
- Add 1.0 program: roadmap improvement tracks and implementation plan by @omkhar in #363
- Add support-tier docs and support-matrix field-parity check (E3) by @omkhar in #364
- Add markdown link and orphan CI check (E4) by @omkhar in #365
- Add OWASP Agentic Top-10 control mapping (A7) by @omkhar in #366
- Document the Rust/Go/shell language-boundary doctrine (D1) by @omkhar in #367
- Add artifact retention policy and drift check (B5) by @omkhar in #368
- Add mutation-score baseline gate (B3 core) by @omkhar in #369
- Add reviewed GitHub Actions allowlist (B4 core) by @omkhar in #370
- Centralize CI tool pins into reviewed policy (B4b) by @omkhar in #371
- Add scheduled mutation-score CI lane (B3b) by @omkhar in #372
- Document and enforce unsafe-code safety invariants (A4) by @omkhar in #373
- Add SLSA v1.0 Build-track gap analysis to the provenance doc (B1) by @omkhar in #374
- Stability contracts: unify the exit-code contract and document it (D8) by @omkhar in #375
- Add a standards watchlist (F3) by @omkhar in #376
- Public contract inventory + drift check (G1 part 1) by @omkhar in #377
- Add maintained architecture diagrams (E2) by @omkhar in #378
- Add Go fuzzing targets and a scheduled fuzz lane (A3) by @omkhar in #379
- Restructure README into tiered entry points (E1) by @omkhar in #380
- Add operator egress policy depth: [network] allowlist surface (A1) by @omkhar in #381
- ^F Treat an empty egress allowlist as deny-all (A1 follow-up) by @omkhar in #382
- ^F Add Rust cargo-fuzz targets for exec-guard classifiers (A3) by @omkhar in #383
- ^F Add exec-guard syscall-shim performance baselines (C5) by @omkhar in #384
- ^F Add CI/CD threat model (B9) by @omkhar in #385
- ^R CI efficiency and reliability program (B8) by @omkhar in #386
- ^f Support-bundle redaction core (G2, 1/3) by @omkhar in #388
- ^F Support-bundle collector + leak-proof + golden (G2, 2/3) by @omkhar in #389
- ^F workcell support-bundle command + audit hardening (G2, 3/3) by @omkhar in #390
- ^B Use snapshot-cloudflare.debian.org CDN mirror (origin fallback) to end mirror-halting CI by @omkhar in #392
- ^D Document injection-policy schema + doc/parser drift check (E5) by @omkhar in #391
- ^D Contributor runbook depth: adapter READMEs + worked examples (E7) by @omkhar in #387
- ^f C2 session-start latency benchmark harness (locally-validatable core) by @omkhar in #393
- ^R D4: extract host-detection into scripts/lib/launcher/host-detect.sh + launcher-contract.md by @omkhar in #394
- ^R D4: extract trusted host-command execution into scripts/lib/launcher/host-exec.sh by @omkhar in #395
- ^R D4: extract Go/Colima host-utility wrappers into scripts/lib/launcher/go-hostutil.sh by @omkhar in #396
- ^d D4: complete launcher-contract.md with required-tools/env/exit-codes/test-flags reference by @omkhar in #397
- ^R D3: migrate git-config-blocklist parity check from verify-invariants.sh to Go by @omkhar in #398
- ^R D3: migrate scripts/workcell hardening invariants from verify-invariants.sh to Go by @omkhar in #399
- ^R D3: migrate scripts/workcell config-safety checks from verify-invariants.sh to Go by @omkhar in #400
- ^R D3: migrate scripts/workcell runtime/gc invariants from verify-invariants.sh to Go by @omkhar in #401
- ^R D3: migrate scripts/workcell managed-profile staging invariants from verify-invariants.sh to Go by @omkhar in #402
- ^R D3: migrate scripts/workcell bootstrap egress-endpoint invariants from verify-invariants.sh to Go by @omkhar in #403
- ^R D3: migrate scripts/workcell bootstrap-audit-metadata invariants from verify-invariants.sh to Go by @omkhar in #404
- ^R D3: migrate scripts/workcell git-index/shadow function-block invariants to Go by @omkhar in #405
- ^R D3: migrate scripts/workcell publish-pr/shadow-mount invariants to Go by @omkhar in #406
- ^R D3: migrate scripts/workcell shadow-enumeration + egress-ip6tables invariants to Go by @omkhar in #407
- ^R D3: migrate home-seeding + provider-wrapper env-scrub invariants to Go (57 checks) by @omkhar in #408
- ^R D3: migrate copilot prefix-scrub + token-handoff invariants to Go (29 checks) by @omkhar in #409
- ^R D3: migrate copilot/docker-run token-handoff invariants to Go (25 checks) by @omkhar in #410
- ^R D3: migrate provider-launcher-authority invariants to Go (30 checks) by @omkhar in #411
- ^R D3: migrate copilot-policy provider-wrapper invariants to Go (22 checks) by @omkhar in #412
- ^R D3: migrate copilot unsafe-flag invariants to Go (31 checks, +present-in-any-file kind) by @omkhar in #413
- ^R D3: migrate copilot upstream-release-verify invariants to Go (24 checks) by @omkhar in #414
- ^R D3: migrate adapter-rule/guard-bash invariants to Go (18 checks, +count-at-least kind) by @omkhar in #415
- ^R D3: migrate inspect/assurance grep-loop invariants to Go (25 checks) by @omkhar in #416
- ^R D3: migrate validator writable-state isolation invariants to Go (23 checks) by @omkhar in #417
- ^R D3: migrate hostutil/entrypoint/colima-egress rg invariants to Go (21 checks) by @omkhar in #418
- ^R D3: migrate dockerfile-pin rg invariants to Go (30 checks) by @omkhar in #419
- ^R D3: migrate validator-env/dispatch loop invariants to Go (13 checks) by @omkhar in #420
- ^R D3: migrate nested caller×required validator-isolation invariants to Go (50 checks) by @omkhar in #421
- ^R D3: migrate fn-block/go-fn-block/git-env invariants to Go (8 checks, +go-function-block kind) by @omkhar in #422
- ^R D3: migrate 4 scattered simple-check clusters to Go (20 checks, 4 subcommands) by @omkhar in #423
- ^R D3: final simple-check sweep to Go (16 checks, 6 subcommands + orphan-helper cleanup) by @omkhar in #424
- ^R D3: add dir-exists/executable/fn-block-regex-absent kinds + migrate 3 checks to Go by @omkhar in #425
- ^R D3: migrate static jq -e adapter-settings invariants to Go (kindJSONExprEval, 4 checks) by @omkhar in #426
- ^d D3: refresh workcellhardening package doc to the current migration state by @omkhar in #427
- ^d Fix orphaned docs/session-startup-benchmarks.md (docs CI green) by @omkhar in #428
- ^r D3: backfill real-repo assertions for the early workcellhardening groups (tests only) by @omkhar in https://gi...
v0.11.2
Immutable
release. Only release title and notes can be modified.
What's Changed
Full Changelog: v0.11.1...v0.11.2
v0.10.7
Immutable
release. Only release title and notes can be modified.
What's Changed
- Add Copilot CLI Tier 1 parity roadmap by @omkhar in #264
- Polish Copilot CLI roadmap docs after review by @omkhar in #266
- ^B Fix four silent error-swallow correctness bugs (sethify findings) by @omkhar in #267
- ^B+^F Security hygiene: TOCTOU fixes, O_NOFOLLOW, GOOS gating, curl caps, mutable banner (sethify findings) by @omkhar in #269
- ^R Dead code & idiom cleanup: runLauncherCompat, git-launcher.rs, stdlib swaps (sethify findings) by @omkhar in #270
- ^R Refactor: adapter table collapse + authpolicy flag-parser dedup (sethify findings) by @omkhar in #271
- ^D Docs/naming fixes: --ui, mode map, Copilot status, package docs (sethify findings) by @omkhar in #272
- ^F+^R CI/CD hygiene: validator cache scope + strict bash + PR pin gate (sethify findings) by @omkhar in #268
- ^F Unify git-config blocklist via policy/ TOML + parity check (closes #275) by @omkhar in #277
- ^R Collapse metadatautil sub-packages into parent (closes #276) by @omkhar in #278
- ^R Split god-files: extract Path, staging.go, bootstrap.go (sethify followup) by @omkhar in #280
- ^R Extract shared PolicySource type into internal/injectionpolicy (closes #274) by @omkhar in #279
- ^B Revert defaults block from scorecard.yml (main-CI fix) by @omkhar in #281
- chore: bump the github-actions group across 1 directory with 3 updates by @dependabot[bot] in #265
- chore: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/markdownlint in the npm_and_yarn group across 1 directory by @dependabot[bot] in #263
- Fix upstream refresh and bootstrap network resilience by @omkhar in #283
- Keep Debian refreshes bootstrap-buildable by @omkhar in #284
- Harden runtime build retry recovery by @omkhar in #285
- Preserve refresh publication validation by @omkhar in #286
- Refresh pinned upstreams by @omkhar in #287
- Harden GitHub API redirect authentication by @omkhar in #288
- Add repository readiness gate by @omkhar in #289
- Refresh pinned upstreams by @omkhar in #290
- Remove dead code: unused exit1, ptyNameBufferSize, redundant loop copy by @omkhar in #291
- Dedup metadatautil/injection helpers; drop unused param by @omkhar in #292
- providerid: derive IsValid from AllProviders; single package doc by @omkhar in #293
- Dedup config-home path; reuse scenarios key helpers by @omkhar in #294
- hostutil: extract parseSessionRootsSingle for single-id session helpers by @omkhar in #295
- publishpr: extract resolveAgainstWorkspace from resolve helpers by @omkhar in #297
- Remove dead bash helpers (shasum precondition, workcell_die, reject_if_protected_provider_path) by @omkhar in #296
- public-node-guard: compute isProtectedProviderFile once in maybeBlock by @omkhar in #298
- check-repo-readiness: fetch tracker issue list once by @omkhar in #299
- trusted-docker-client: dedup duplicated registry CA blocks by @omkhar in #300
- runtime wrappers: hoist shared env pin/sanitize into runtime-user.sh by @omkhar in #301
- execveat: reuse classify_loader_target / loader_targets_mutable_native_exec by @omkhar in #302
- colima-timeout harness: extract assert_contains for forwarded-arg checks by @omkhar in #303
- execveat: rustfmt the loader_targets_mutable_native_exec assignment by @omkhar in #304
Full Changelog: v0.10.6...v0.10.7
v0.10.6
Immutable
release. Only release title and notes can be modified.
What's Changed
- Fix upstream refresh and workflow gates by @omkhar in #170
- chore: bump github/codeql-action from 4.35.1 to 4.35.2 in the github-actions group across 1 directory by @dependabot[bot] in #169
- Fix publish-pr signed range enforcement by @omkhar in #171
- Refresh pinned upstreams by @omkhar in #172
- Refresh pinned upstreams by @omkhar in #174
- Hash-pin zizmor workflow install by @omkhar in #175
- Record Phase 10-12 roadmap gates by @omkhar in #176
- Fix provider-bump check status capture in update-upstream-pins.sh by @omkhar in #177
- Gate release.yml preflight on main checks being green by @omkhar in #178
- Add timeout-minutes to every workflow job by @omkhar in #179
- Bound HTTP timeout, request context, and response body in provider_bumps fetches by @omkhar in #180
- Use cmd.Output() not CombinedOutput() for gh api ruleset detail by @omkhar in #181
- Centralize sanitized-entrypoint preamble across 10 host-side scripts by @omkhar in #182
- Modernize 58 sort.Strings call sites to slices.Sort by @omkhar in #183
- Fix correctness cluster in internal/hostutil/launcher.go (6 bug fixes) by @omkhar in #184
- Fix small-bug cluster: scenarios, metadatautil, scripts/workcell trap, mutation runner by @omkhar in #185
- Install full validator toolchain via install-dev-tools.sh; align release.yml zizmor to 1.24.1 by @omkhar in #187
- Rename cmd/workcell-treecompare to cmd/workcell-tree-compare by @omkhar in #189
- Link closed-finding evidence from SECURITY.md by @omkhar in #188
- Add control-plane lockstep invariant under verify/invariants/ by @omkhar in #190
- Introduce internal/providerid constants and migrate 71 raw-string sites by @omkhar in #191
- Docs consistency pass: man, README, codex adapter README, CONTRIBUTING, dead markdownlint rule, auth unset by @omkhar in #186
- Small CI/CD + 🔵 cleanup cluster: ghcr login, cp -RP, map sort, EIO, max-filesize, pin-hygiene comment by @omkhar in #193
- Extract internal/tomlsubset canonical parser and dedupe stripComment across 5 packages by @omkhar in #192
- Centralize per-provider tables in internal/adapters/{p}/ by @omkhar in #194
- Delete tests and doc.go for dormant internal/policybundle (1 of 2 deletion PRs) by @omkhar in #198
- Add dated --ack-breakglass=YYYY-MM-DD and --ack-arbitrary-command=YYYY-MM-DD forms by @omkhar in #195
- Make release attestations fail-closed with WORKCELL_RELEASE_NO_ATTEST opt-out by @omkhar in #196
- Move forbidden host-path enumeration into policy/forbidden-host-paths.toml by @omkhar in #197
- Shrink dormant internal/policybundle/policy_bundle.go to stub vars + PolicySource (1 of 2) by @omkhar in #199
- Tidy mutation runner with goCmd helper, rename resolvePathLikePython, drop Python-mirror comments by @omkhar in #200
- Extract GitHub-release helpers into internal/host/release (1 of hostutil split series) by @omkhar in #201
- Delete dormant internal/policybundle (final step of D6) by @omkhar in #202
- Extract support-matrix into internal/host/supportmatrix (2 of hostutil split series) by @omkhar in #203
- Extract sessions package into internal/host/sessions (3 of hostutil split series) by @omkhar in #204
- ^R Extract Colima + profile-lock cluster into internal/host/launcher by @omkhar in #205
- ^R Extract host-state/mounts/audit cluster into internal/host/hoststate by @omkhar in #206
- ^R Finish hostutil split: move remaining helpers into internal/host/launcher, delete internal/hostutil by @omkhar in #207
- ^R Extract workflow validators into internal/metadatautil/workflows by @omkhar in #208
- ^R Extract hosted-controls policy helpers into internal/metadatautil/hostedcontrols by @omkhar in #209
- ^R Move VerifyGitHubHostedControls into internal/metadatautil/hostedcontrols by @omkhar in #210
- ^R Extract CheckPinnedInputs into internal/metadatautil/pinnedinputs by @omkhar in #211
- ^A Validate AppArmor/SELinux in daemon and post-launch HostConfig.SecurityOpt by @omkhar in #212
- ^R Collapse cmd/workcell-hostutil launcher switch into a registry table by @omkhar in #213
- ^R Convert cmd/workcell-metadatautil dispatch to a registry pattern by @omkhar in #214
- ^R Move install-deps mock binaries out of verify-invariants.sh into harnesses/ by @omkhar in #215
- ^R Bootstrap internal/sessionctl: move session_usage help text to Go by @omkhar in #216
- ^R Move session_timeline_main into internal/sessionctl/TimelineMain by @omkhar in #219
- ^R Move process/colima harness bodies into verify/invariants/harnesses/process-colima/ by @omkhar in #220
- ^R Move git-probe heredocs + gemini-auth-selection harness into verify/invariants/harnesses/ by @omkhar in #221
- ^R Translate session_logs_main into internal/sessionctl/LogsMain by @omkhar in #222
- ^R Extend internal/tomlsubset with shared tokenizer and AST by @omkhar in #223
- ^R Extract auth_usage and policy_usage heredocs into internal/authpolicy by @omkhar in #224
- ^R Extract publish_pr_usage heredoc into internal/publishpr by @omkhar in #225
- ^R Migrate authpolicy and authresolve to shared tomlsubset by @omkhar in #228
- ^R Translate auth_main into internal/authpolicy/AuthMain by @omkhar in #230
- ^R Translate session_attach_main into internal/sessionctl/AttachMain by @omkhar in #227
- ^R Translate publish_pr_main validators into internal/publishpr (24.2a) by @omkhar in #231
- ^R Translate policy_main into internal/authpolicy/PolicyMain by @omkhar in #229
- ^R Translate colima helpers into internal/host/launcher by @omkhar in #226
- ^R Migrate injection to shared tomlsubset (closes Section F) by @omkhar in #234
- ^R Translate profile path helpers into Go by @omkhar in #235
- ^R Translate prepare_injection_bundle/direct_mounts into internal/injection by @omkhar in #236
- ^R Translate docker client + process helpers into Go by @omkhar in #237
- ^R Translate session_stop_main into internal/sessionctl/StopMain by @omkhar in #238
- ^R Translate session_send_main into internal/sessionctl/SendMain by @omkhar in #232
- ^R Wire publish_pr_main shim through publishpr.PublishPRMain (24.2b) by @omkhar in #233
- ^R Translate session_delete_main into internal/sessionctl/DeleteMain (22.6) by @omkhar in #239
- ^R Translate session_monitor + session_main dispatcher (22.7) by @omkhar in #240
- ^R Collapse cmd binaries: 7 thin cmds into 3 umbrellas (26) by @omkhar in #241
- ^B Fix sethify blockers + cliexit foundation (fix-1a) by @omkhar in #242
- ^R Sessionctl dispatch rename + shim dedup (fix-1b) by @omkhar in #243
- ^R Quality cleanup + pathutil/stateroot extraction (fix-2) by @omkhar in #244
- ^R Extract internal/shellproto for bash↔Go KEY=VALUE protocol (fix-3) by @omkhar in #245
- ^R Cmd docs + naming polish (fix-4) by @omkhar in #246
- ^B Sethify round-2 critical: red + near-red + cliexit completion (fix-5) by @omkhar in #247
- ^R Sethify round-2 architecture closures (fix-6) by @omkhar in #248
- ^R Sethify round-2 docs + polish + Q4 (fix-7) by @omkhar in #249
- ^B Sethify round-3 critical follow-up (fix-8)...
v0.10.5
Immutable
release. Only release title and notes can be modified.
What's Changed
Full Changelog: v0.10.4...v0.10.5
v0.10.3
Immutable
release. Only release title and notes can be modified.
What's Changed
Full Changelog: v0.10.2...v0.10.3
v0.10.2
Immutable
release. Only release title and notes can be modified.
v0.10.1
Immutable
release. Only release title and notes can be modified.
v0.10.0
What's Changed
- docs: formalize release and async review policy by @omkhar in #100
- Document release review workflow and refresh roadmap by @omkhar in #101
- [codex] Harden managed runtime and validation boundaries by @omkhar in #102
- [codex] Remove remote heavy validation lane by @omkhar in #103
- [codex] Align hosted controls with current review posture by @omkhar in #105
- chore: bump docker/build-push-action from 7.0.0 to 7.1.0 in the github-actions group by @dependabot[bot] in #104
- Align docs with current session and rollout state by @omkhar in #106
- Enforce traceability for release-facing docs by @omkhar in #108
- Repair mainline validate-repo baseline by @omkhar in #110
- Refresh release pins and cap Claude at 2.1.104 by @omkhar in #109
- Fix session runtime control and resize regressions by @omkhar in #107
- Refresh release inputs with a Claude 2.1.104 holdback by @omkhar in #112
- Add recurring release readiness sweeps by @omkhar in #113
- Harden smoke host-path handling against symlink traversal by @omkhar in #111
- Harden runtime control-plane boundaries by @omkhar in #114
- Align hosted-controls policy with review-gated main by @omkhar in #115
- Release v0.10.0 by @omkhar in #116
Full Changelog: v0.9.3...v0.10.0