Skip to content

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 07 Sep 07:55
· 10 commits to main since this release
7574adf

Vendor the Codex CLI at a pinned version, and split the capability that says
which build runs from the one that says who signed it.

codex installs its own copy from npm at an exact version, refusing any tarball
but the one whose SHA-512 this repository commits, and executes it by absolute
path. That is what keeps the decoder and the fixtures it was written against
describing the same CLI: an agent that updates itself moves its event schema
silently, and the break then lands on a user mid-run instead of on a red test at
the bump.

Pinner is that guarantee and nothing more. Installer is Pinner plus provenance —
a named publisher signed the artifact, verified against a trust anchor embedded
here — which claudecode does and codex cannot. OpenAI publishes sigstore bundles
for its linux-musl release assets alone; npm attests every platform, darwin
included, but verifying a Sigstore bundle in Go costs an order of magnitude more
dependencies than this library carries, so that attestation is checked by hand
when the pin moves. docs/adr/0004 records the alternatives and the procedure.

A message's content is a string or a list of blocks, and claudecode modelled
only the list. A bare string is a shape the CLI emits, so a stream that was
working failed the whole run, and it surfaced as the provider being unavailable
rather than as anything a caller could act on.

Breaking:

  • codex.New takes a providers root and returns an error. Running whichever
    codex is on PATH is codex.NewOnPath().
  • agentic.Installer gains SigningIdentity(). A provider that vendors a binary
    without verifying a publisher's signature implements agentic.Pinner instead,
    and the driver asserts on Pinner wherever it means "can install".
  • Driver.SigningIdentity() answers ErrProvenanceUnsupported, wrapping
    ErrInstallUnsupported for a provider that vendors nothing at all.

Full changelog: v0.3.0...v0.4.0