Releases: saroo98/loom
Release list
Loom 1.8.30
Loom 1.8.30
This release adds exact, privacy-safe release assurance without changing Loom's planning engine or ordinary planning behavior.
- Separates conservative source-tree readiness from readiness for a finished release.
- Binds release evidence to the exact commit, tag, plugin archive, reproduced archive, and native helpers.
- Validates typed evidence for CI, exact-cut, privacy, provenance, SBOM, reproducibility, rollback, and fresh Codex App observation.
- Distinguishes supported-but-unverified targets from unsupported, experimental, stale, expired, or conflicting evidence.
- Rejects private paths, owner data, prompts, task identities, environment values, and raw logs from public release evidence.
- Publishes a machine-readable release passport and evidence graph with the immutable release assets.
The canonical plugin was built reproducibly from 7c18cbbff7a345ce85d69c50adb9d54a9ba12dc2, verified across Windows, Linux, and macOS, and signed through Loom's established release authority.
Loom 1.8.29
Loom 1.8.29
This patch release makes natural plan revision reliable when a compact plan grows into a full planning lifecycle.
- Regenerates the correct lifecycle when an exact revision promotes a Tier-S plan to Tier M.
- Preserves the existing plan until the revised plan is fully authored and sealed.
- Adds a live-prompt regression for the compact-to-full revision path.
- Retains exact-plan continuity, stale-state refusal, and cross-project isolation.
The canonical plugin was built reproducibly from f57d84a7fc73a3ad64b1b666aaef715efd54fd8d, verified across Windows, Linux, and macOS, and signed through Loom's established release authority.
Loom 1.8.28
Loom 1.8.28
This patch release makes plan review decisions work reliably across normal Codex turns.
- Recovers the exact completed plan for a later natural-language revision or start request.
- Preserves exact structured plan references as the highest-priority path.
- Refuses ambiguous, changed, stale, malformed, or cross-project plan recovery.
- Refreshes time-bound Codex host evidence for the signed release cut.
The canonical plugin was built reproducibly from aac356bfb172c761491aa8fcf3080fde4039415b, verified across Windows, Linux, and macOS, and signed through Loom's established release authority.
Loom 1.8.26
Loom 1.8.26
Loom 1.8.26 completes the corrective release for plan review, revision, and exact-plan execution.
What changed
- Natural revision requests remain bound to planning intent, including requests that explicitly
prohibit implementation. - Completed plans expose a deterministic structured review projection with the full Markdown plan
retained as the portable fallback. - Starting an approved plan returns the exact work-order completion contract needed to capture
real evidence and close only the authorized work. - Stale, changed, or mismatched plan state continues to fail closed before implementation.
Validation reliability
- Windows fast-gate timing now uses a bounded platform-specific allowance for measured process
startup overhead while preserving the same test inventory and assertions. - Exhaustive release verification retains its full test matrix with a larger bounded supervisor
window on Windows. - The clean-room verifier now derives its outer deadline from the exact-cut suite ceiling plus a
fixed shutdown and receipt margin, preventing independent timeout settings from drifting apart. - Validation failures report the primary failing step directly.
Release integrity
This release is built from the exact public main source, packages separately built native helpers
for Windows, macOS, and Linux on x64 and ARM64, and is published only after exact-cut, hosted CI,
signature, checksum, release-subject, and post-install checks pass.
Loom 1.8.25
Loom 1.8.25
Loom 1.8.25 adds a complete plan-review and revision surface while preserving the sealed planning, validation, freshness, continuation-authority, privacy, and local-first boundaries.
Plan review and revision
- Presents every authored plan directly in the conversation with a complete Markdown fallback.
- Shows the full plan for small work, a bounded review for medium work, and the authorized frontier for large work.
- Includes a contained clickable plan link when the host supports local file links.
- Lets the owner request a revision and review a deterministic semantic diff.
- Rejects no-op revisions, stale worlds, changed plans, tampered bindings, and replayed revision state.
- Starts only the exact reviewed plan, bound to its project, world, contract, pack, file, and revision identities.
- Uses only the officially supported portable MCP text and structured-content surface. No unsupported native viewer capability is claimed.
Verification
- Exact source commit:
e3a27f421bbe2e958e84d8a9b2c75acee88b13d2 - Exact public-cut SHA-256:
3380919aad5288cc18cdd3709bd932f8e4b675c3c242d8cc14c511e2816e98e9 - Canonical plugin SHA-256:
b67ee6b694510c4d53a7996604b332cd7e8471b4796c041a7e59a504687c57c4 - Release-subject bundle SHA-256:
7c0916369192ed22f0fc8e6d0bac1a90222fe3620f909de716144787fb53c4c9 - Exact-cut suite: 1,371 tests, 0 failures, 0 errors, 24 capability skips
- Focused Phase 5 suite: 103 tests passed
- Production Phase 5 suite: 11 tests passed
- GitHub quality matrix: 26/26 jobs green
- Native compatibility matrix: 21/21 jobs green across Windows, Linux, macOS, Python 3.10–3.14, x64, and ARM helpers
- Deterministic packaging: two independently built 487-file plugin directories matched exactly
- Release firewall: clean across all 489 finalized package files
The release tag is SSH-signed. The plugin contains threshold-signed release metadata and reproducible native-helper evidence.
Loom 1.8.24
Loom 1.8.24
Loom 1.8.24 completes the current Proofline and Completion release cut and fixes three acceptance and verification defects found before publication.
Fixed
- Preserves complete blocked-state owner messages instead of losing the concrete result or next action at the two-line presentation boundary.
- Bounds Windows CLI contract probes so a slow or unavailable executable cannot starve the hosted verification matrix.
- Gives the recovery-concurrency regression enough bounded time on loaded Windows runners while retaining exact failure diagnostics and guaranteed cleanup.
Verification
- Exact source commit:
cd4e9ea8ceae088d9f4942fb2f6404c6f55d806a - Exact public-cut SHA-256:
a7d258c270ce345ad7450177675a966150e506b0ad8cdfee2197cb218cc6c441 - Canonical plugin SHA-256:
ee8f229e01037b0dc701122d7161f1363dcc08b653039c170e50864ddd28343a - Release-subject bundle SHA-256:
697aa578546c2940693830ec744239d14eee230231a75f43987a318c8ae5096f - Exact-cut suite: 1,338 tests, 0 failures, 0 errors, 24 capability skips
- GitHub quality matrix: 26/26 jobs green
- Native compatibility matrix: 21/21 jobs green across Windows, Linux, macOS, Python 3.10–3.14, x64, and ARM helpers
- Deterministic packaging: two independently built 505-file plugin directories matched exactly
- Release firewall: clean across all 507 finalized package files
The release tag is SSH-signed. The plugin contains threshold-signed release metadata and reproducible native-helper evidence.
Loom 1.8.23
Loom 1.8.23
Loom 1.8.23 fixes the project-write prohibition contract discovered during fresh-host acceptance of 1.8.22.
Fixed
- Treats requests such as “do not implement it or modify project files” as an explicit prohibition on project-local writes.
- Recognizes equivalent wording with optional pronouns and “project files” or “project-local files”.
- Fails closed before creating
plans/or any other project-local metadata when the owner forbids project changes. - Preserves the existing persistent planning path when the owner permits project-local plan files.
Verification
- Exact source commit:
bd9840c79bb5feafd3a36abbdbd110ee33c88222 - Exact public-cut SHA-256:
e475dc49dd6a0569f0253dfa25f3d010a23dca846d73cb98eca7bdc21d5abc37 - Canonical plugin SHA-256:
d83b262a47b807c27476bdaeca6c940778b80e006c3cdbd128a1567a2f4f0cc4 - Release-subject bundle SHA-256:
cdb9fc8758aa8825154e8fa7485cb49cb8d382db12938363e427b8140de3a789 - Exact-cut suite: 1,334 tests, 0 failures, 0 errors
- Clean-room verification: passed in a disposable home
- GitHub quality matrix: 26/26 jobs green
- Native compatibility matrix: 21/21 jobs green across Windows, Linux, macOS, Python 3.10–3.14, x64, and ARM helpers
The release tag is SSH-signed. The plugin contains threshold-signed release metadata and reproducible native-helper evidence.
Loom 1.8.22
Loom 1.8.22
Loom 1.8.22 completes the Proofline and Completion release slice and corrects
the final clean-room receipt-status boundary found while verifying 1.8.21.
What changed
- binds completion claims to exact verification subjects, evidence, and
contradiction states; - keeps proof details available without forcing internal lifecycle vocabulary
into the default owner message; - strengthens completion, review, repair, recovery, reopening, and real-host
acceptance behavior; - verifies the release cut through deterministic rebuilds, clean-room
execution, privacy checks, and the hosted platform matrix; - writes bounded clean-room transcripts durably during verification;
- accepts the canonical
verifiedclean-room receipt state while continuing
to fail closed for nonverified receipts.
Compatibility
- Existing v2 recovery receipts remain readable.
- Existing supported Loom project and owner-state formats remain compatible.
- The signed update path preserves the private Loom vault and activation
history.
Verification subject
- Source commit:
0021a61449bb4d3d1832d68ba3f4b1400a7eb0e9 - Exact public-cut SHA-256:
a24c5464331880b9bb93da1297b33c5b9873d36d7f19704c316e4ad8d148e494 - Generated inventory: 1,333 tests across 119 test modules
The release assets include the canonical plugin archive, SHA256SUMS, and
RELEASE-SUBJECT.json.
Loom 1.8.19
Loom 1.8.19
Loom 1.8.19 removes false planning blockers found during real project use and prepares the current public main source as an immutable signed release.
What changed
- Explicit plan-only requests remain planning requests even when they describe a substantial application.
- Workspace inspection uses bounded classification instead of treating every ignored root as unresolved by default.
- Large repositories can return a safe partial planning contract instead of failing only because a complete workspace hash exceeds its time bound.
- Read-only planning keeps implementation changes prohibited while disclosing the bounded project-local plan artifacts Loom creates.
- Signed updates preserve the active owner-vault schema and convert incompatible activation state into a bounded error instead of terminating the MCP transport.
Verification
- Exact source commit:
c09e99d2d0794e72e2a2226e28fc6c0d44518e65 - Quality CI: 26/26 jobs passed on Windows, Linux, and macOS with Python 3.10 through 3.14.
- Native compatibility: 21/21 jobs passed across x64 and ARM helper targets.
- Current test inventory: 1,296 tests.
- Exact public-cut SHA-256:
3808ed2b61fa63e507ac1e3c8ebde788c425bb1029b2dea23e98a9dd9ebeaf85 - Canonical plugin SHA-256:
d14d7ab133ea3341a55af17bd53400528982470de36a6946fcbe977ac5b027b9 - Release subject:
b36522612788da214ffad721d62eb416e3bea5ad8d96911b1af64eab9b18eac2 - Final package firewall: clean across 484 files and four private-path token classes.
The release remains local-first and contains no owner vault, telemetry, personal project state, or private planning material.
Loom 1.8.18
Loom 1.8.18
Loom 1.8.18 fixes signed upgrades from older active runtimes whose trust-anchor module predates the owner-vault path resolver.
What changed
- Signed upgrades from Loom 1.8.15 now preserve the established owner-vault location.
- Newer trust-anchor modules continue to provide their explicit vault resolver.
- A missing legacy resolver falls back only to the documented
vault/owner.sqlite3path. - A malformed resolver fails closed.
Verification
- Exact source commit:
dc7a2f1aa0fef722042b7bb28173ec072cb6fdcf - Quality CI: 25/25 jobs passed on Windows, Linux, and macOS with Python 3.10 through 3.14.
- Native compatibility: 21/21 jobs passed across x64 and ARM helper targets.
- Canonical plugin SHA-256:
6c3c42d5b800ff12ffc12cb076b191f1723617918b652e262dfe7c9c2bb5b103 - Release subject:
955ea697654dacb0a9a5cdf0dc8326770ae067bec031b3e09fdd0e5f4221e3e5 - Final package firewall: clean across 461 files and five private-owner token classes.
The release remains local-first and contains no owner vault, telemetry, personal project state, or private planning material.