Skip to content

ContextLattice v5.0.2 - Unsigned Technical Preview

Latest

Choose a tag to compare

@github-actions github-actions released this 26 Aug 22:53

ContextLattice v5.0.2: Proof Bound to the Patch

v5.0.2 is the distribution-proof follow-up to V5.0.1. It carries the same retrieval-readiness runtime: Qdrant collection, dimension, payload indexes, memory migration, and native source ownership must all be ready before deployment health turns green.

V5.0.1 source tags remain immutable. Its public installers were reproduced locally, but paid packaging correctly failed closed because its Frontier release provenance still identified V5.0.0. V5.0.2 advances the release identity instead of rewriting that tag.

What Changed

  • Paid release provenance is regenerated from the exact V5.0.2 private tested source, a closed-world source manifest, a release-bound eval ledger, and an immutable private proof commit.
  • Commercial auditing now declares private launch documents required, omitted, or auto. Partial projections fail; the paid lane requires all private launch-planning files to be absent.
  • Public, paid, local, and hosted release identity advances together. Retrieval behavior is unchanged from the V5.0.1 patch.

Release Gate

V5.0.2 release authorization is fail-closed. The private proof commit, provenance binding, exact public and paid tags, local artifact audits, and live local/hosted readbacks must all pass before publication. A source tag without that complete chain is not release authority.

GitHub-hosted checks are supplemental. Local deterministic validation remains the release authority.

Upgrade and Rollback

Preserve Qdrant, memory, task, session, Passport, continuation, graph, and policy volumes. Rebuild only the inventoried Gateway and MCP adapter, then require /readyz, source-bound /health, and the structured retrieval canary to pass.

Rollback remains tag-pinned. Restore the prior Gateway and adapter images without deleting or recreating data volumes.