Skip to content

Releases: starlight-protocol/starlight

v5.0.0-alpha.5 — Mission Studio

Pre-release

Choose a tag to compare

@godhiraj-code godhiraj-code released this 03 Oct 05:21

Starlight now includes Mission Studio, a local workspace that turns the existing agent runtime into something you can try and inspect visually.

  • Run two working presets: a verified order report and an HTTP service-health report.
  • Follow agent progress, inspect results and evidence, preview generated Markdown, and export JSON reports.
  • Validate custom missions, load your own agents at startup, set time budgets, and cancel active work.
  • Browse saved history with explicit unfinished-checkpoint and storage-error states.

Start from a checkout with Node.js 22+:

npm ci
npm run studio

Open the private local URL printed in the terminal. The included examples require no API keys.

The server binds only to 127.0.0.1, uses a fresh session token for API access, rejects unexpected Host/Origin headers, and bounds request sizes, active runs, streams, artifact previews, and shutdown. Custom agents are trusted local code; this is a single-user local tool. There is no hosted execution, automatic retry/resume, or universal planner. The wire protocol remains 1.0.

The attached package was checked through installation into a clean directory, both real examples, Studio API/static assets, cancellation, artifact preview, and persisted history. The release gate also runs unit/integration and protocol tests, lint, TypeScript/schema/documentation checks, a cross-process proof, website checks, and a full dependency audit. Compatible fixes for brace-expansion and fast-uri address newly reported development-dependency advisories.

Studio guide · Website · Changelog

Preview release: this is the current 5.x platform. Legacy v1.3.4 is the old browser implementation. Download the .tgz and SHA256SUMS below; this release does not publish a new npm registry version.

v5.0.0-alpha.4 - API agents and mission preflight

Choose a tag to compare

@godhiraj-code godhiraj-code released this 20 Sep 17:53

Starlight 5.0.0-alpha.4 — API agents and mission preflight

Missions can now read JSON APIs through a reusable agent, verify domain results, and hand them to subsequent steps. Plans can also be checked before any agents are loaded or executed.

  • HTTP JSON agent: createHttpJsonAgent supports GET requests to explicitly allowed HTTP(S) origins, request deadlines, bounded decoded response sizes, cancellation, HTTP evidence, and optional verification. Redirects and automatic retries are disabled.
  • Service-health workflow: starlight demo --example service-health starts a temporary local fixture endpoint, fetches and verifies three health records, then writes and reads back a Markdown report. It demonstrates real HTTP against sample data without credentials.
  • Mission preflight: starlight validate mission.json and SDK validateMission normalize and validate a mission without loading agents, making requests, or creating run files.

Requires Node.js 22+. Wire protocol 1.0 remains unchanged. Existing agents, the default file-report demo, run storage, and mission APIs remain supported.

Try the exact release

Download the attached archive and verify it against SHA256SUMS:

npm install ./starlight-protocol-starlight-5.0.0-alpha.4.tgz
npx starlight demo --example service-health --events --timeout-ms 10000
npx starlight runs --status completed --limit 10

The attached archive is the release distribution; these commands do not assume a registry publication.

Verification and scope

The release gate passes 79 tests, 19 protocol conformance cases, lint, TypeScript declarations, schema and documentation checks, authenticated multi-process execution, demo scenarios, and website builds. Installed-package checks exercise both demos, run history, report inspection, and mission validation. The dependency audit reports zero vulnerabilities.

HTTP regressions cover blocked origins, redirects, malformed data, compressed and streamed response limits, configured credentials, failed verification, request deadlines, and cancellation of stalled streams.

Agents remain trusted code. URL origin restrictions are not a network sandbox or DNS policy. API credentials belong in agent configuration, and domain validation remains agent-defined. Preflight checks plan structure, not endpoint health or future execution success. This remains an alpha release.

API agents and mission validation · Website · Changelog

v5.0.0-alpha.3 - Mission reliability

Pre-release

Choose a tag to compare

@godhiraj-code godhiraj-code released this 20 Sep 16:36

Starlight 5.0.0-alpha.3 — mission reliability

This preview adds durable progress inspection to the general-purpose agent platform. A CLI process crash previously could leave an empty reserved report; runs now save atomic snapshots before and after every step, retaining the last recorded results and evidence.

  • Progress storage: FileRunStore is enabled by default in the CLI and optional in AgentPlatform. Failed checkpoint writes stop new work and reject the run handle.
  • Run history: starlight runs --status failed --limit 20 lists saved summaries across process exits; inspect reads a complete report.
  • Mission deadlines: SDK timeoutMs and CLI --timeout-ms bound routing, capacity waits, execution, verification, and inter-step persistence. Deadlines propagate cancellation to remote agents.
  • Progress events: SDK subscribe and CLI --events expose immutable lifecycle snapshots. CLI events go to stderr, preserving final JSON on stdout.
  • Diagnostics: step timings, final-write retention protection, isolated observer errors, and bounded retries for Windows checkpoint rename locks.

Requires Node.js 22+. Wire protocol 1.0 is unchanged. Existing agents and final reports remain supported. This is an alpha, not a stable or production-readiness claim.

Install this exact preview

Download the attached package and verify it against SHA256SUMS, then:

npm install ./starlight-protocol-starlight-5.0.0-alpha.3.tgz
npx starlight demo --events --timeout-ms 10000
npx starlight runs --status completed --limit 10

This release is distributed as the attached archive; these instructions do not assume it is published to the npm registry.

Validation

The release gate covers 70 tests, lint, TypeScript declarations, schema and documentation checks, 19 protocol conformance cases, authenticated multi-process execution, demo scenarios, website builds, and installation of the packed artifact into a fresh project. The package export, CLI demo, saved report, and history command are verified from that installation. The full dependency audit reports zero vulnerabilities.

Crash tests terminate a CLI process after an external effect and verify the retained checkpoint. Additional tests inject storage faults before and after effects, read concurrently with snapshot replacement, and exercise remote deadlines and late synchronous results.

Recovery boundary

A saved running step is unfinished evidence, not proof of a live process. It may already have caused an external effect. Checkpoints do not automatically resume or replay agents, guarantee exactly-once effects, or roll back work. Reconcile ambiguous effects before submitting a fresh mission.

Run storage, deadlines, and crash semantics · Website and demo · Changelog

v5.0.0-alpha.2 — General-purpose agent platform

Choose a tag to compare

@godhiraj-code godhiraj-code released this 05 Sep 05:28

Starlight v5.0.0-alpha.2 — General-purpose agent platform

Starlight 5.x introduces a general-purpose Node.js agent platform: define goals, context,
constraints, and ordered mission steps; register your own agents; inspect verified outcomes.
This alpha supersedes the browser-specific 1.x implementation for new platform development.

Included

  • AgentPlatform SDK with registration, routing, optional completion verification, result handoff,
    cooperative cancellation, bounded history, and inspectable mission reports.
  • The starlight CLI for running missions, discovering agents, and inspecting saved reports.
  • Authenticated remote agents over JSON-RPC/WebSocket; wire protocol remains 1.0.
  • Verified file-output example, adversarial lifecycle coverage, and an independent protocol TCK.
  • Updated public website, six captured run reports, and a narrated 3:36 walkthrough with captions.

Install the attached package

Requires Node.js 22 or newer. Download the .tgz asset and verify it against SHA256SUMS.
In a new project directory:

npm init -y
npm install /path/to/starlight-protocol-starlight-5.0.0-alpha.2.tgz
npx starlight demo

This GitHub release distributes an installable npm archive. It does not imply publication to
the npm registry; use the attached archive or the tagged source.

Migration and boundaries

5.x is a breaking replacement for the browser-era project, not a drop-in update to 1.3.4.
The legacy launcher, browser self-healing architecture, and historical language SDKs are outside
the supported 5.x surface. Read the migration guide before upgrading.

Agents supply tools, models, planning, and semantic constraint enforcement. They are trusted code
with host permissions. Cancellation is cooperative; run history is in memory; saved reports
are not durable checkpoints. This is an alpha, not a production-readiness claim.

Verification

The release commit passes the full clean-checkout gate: 59 tests, 19 protocol conformance checks,
lint, TypeScript/schema validation, demo scenarios, authenticated multi-process proof, installed
package checks, website build, and a dependency audit with zero reported vulnerabilities.
Both Linux Node.js 22 and 24 CI jobs must pass before publication. The attached archive is also
installed into a fresh consumer directory and exercised directly before uploading.

Release commit: a08ba8b6ff2ee77de061ad68b3de0a60e0491279.
Node 22/24 release gates and
website deployment verification passed.
The attached package passed a fresh installation, demo, saved inspection, and multi-process proof.

LEGACY — v1.3.4 (old browser implementation)

Choose a tag to compare

@godhiraj-code godhiraj-code released this 11 Jan 11:02
c3b5e2b

Legacy v1.3.4 — use 5.x for the current platform

Get the current platform: v5.0.0-alpha.5 →

Important

This is the old browser-specific implementation. It is not the current general-purpose agent platform.
GitHub's Latest badge applies to full releases, so it still appears here while Starlight 5.x is in alpha.
For current platform development, download v5.0.0-alpha.5 using the link above.

Migration guide · Current website and demo

Historical v1.3.4 release notes

Added

  • Generic Semantic Perception: hub.js now implements generic class-name semantic extraction. It correctly identifies icon-only elements (like "Shopping Cart") even when they contain dynamic badges (e.g., "2"), eliminating the need for hardcoded selectors.
  • Reporting Integrity: intent_nli_test.js now strictly enforces minSteps verification. Partial execution (e.g., LLM stopping after one step) is now correctly flagged as a failure.
  • Self-Healing: Verified that the Hub learns selecting mappings on the fly (click:Shopping Cart -> a:has-text("2")) and persists them to starlight_memory.json, making subsequent runs instantaneous.

Added

  • JWT Authentication System (src/auth/jwt_handler.js)

    • Industry-standard JWT token generation and verification
    • HMAC-SHA256 signing with timing-safe comparison
    • Configurable token expiration (default: 3600s)
    • Token refresh capability for long-running sessions
    • Secure random secret generation
  • Input Validation Pipeline (src/validation/schema_validator.js)

    • Comprehensive JSON schema validation for all message types
    • Method-specific validation with strict patterns
    • Field type checking, length limits, and pattern matching
    • Prevention of malformed or malicious payloads
  • PII Protection System (src/utils/pii_redactor.js)

    • Automatic detection and redaction of sensitive data
    • Email addresses, phone numbers, credit cards, SSNs
    • JWT tokens and API keys
    • Recursive object sanitization
    • Compliance modes: alert, block, or redact
  • Encryption Layer (src/warp_sanitizer.js)

    • AES-256-GCM encryption for sensitive data
    • Secure key generation and management
    • Optional encryption for warp files
    • Key rotation support

Protocol reslience: Security hardening and mission launcher ui changes (with mobile emulation)

Choose a tag to compare

@godhiraj-code godhiraj-code released this 11 Jan 09:59
43a474c

Enterprise Security Hardening

🔒 Comprehensive Security Infrastructure

Added

  • JWT Authentication System (src/auth/jwt_handler.js)

    • Industry-standard JWT token generation and verification
    • HMAC-SHA256 signing with timing-safe comparison
    • Configurable token expiration (default: 3600s)
    • Token refresh capability for long-running sessions
    • Secure random secret generation
  • Input Validation Pipeline (src/validation/schema_validator.js)

    • Comprehensive JSON schema validation for all message types
    • Method-specific validation with strict patterns
    • Field type checking, length limits, and pattern matching
    • Prevention of malformed or malicious payloads
  • PII Protection System (src/utils/pii_redactor.js)

    • Automatic detection and redaction of sensitive data
    • Email addresses, phone numbers, credit cards, SSNs
    • JWT tokens and API keys
    • Recursive object sanitization
    • Compliance modes: alert, block, or redact
  • Encryption Layer (src/warp_sanitizer.js)

    • AES-256-GCM encryption for sensitive data
    • Secure key generation and management
    • Optional encryption for warp files
    • Key rotation support

Protocol Specification Updates

  • Security Considerations Section (spec/STARLIGHT_PROTOCOL_SPEC_v1.0.0.md)
    • JWT authentication requirements (Section 8.2)
    • Input validation requirements (Section 8.3)
    • Data protection requirements (Section 8.4)
    • Authorization and RBAC (Section 8.5)
    • Compliance considerations (Section 8.6)
    • Security configuration options (Section 8.7)
    • Security monitoring (Section 8.8)
    • Threat model (Section 8.9)

Hub Security Enhancements

  • Token validation on registration
  • Message schema validation before processing
  • CSS selector injection prevention
  • XSS protection with HTML escaping
  • Rate limiting per client
  • Resource limits (memory, screenshots, traces)

[UNRELEASED] Phase 14.2 - Universal Semantic Resolver

Semantic Resolution Overhaul

Fixed

  • Invalid CSS Selectors: Removed [@click], [v-on:click], [ng-click], i[class*="fa-"], i[class*="material-"] from INTERACTIVE_SELECTORS that caused querySelectorAll to throw SyntaxError and crash semantic resolution
  • Checkout Button Mismatch: Fixed fuzzy matcher incorrectly resolving clickGoal('Checkout') to #cart_contents_container instead of the actual button#checkout
  • Input Button Selectors: Added input[type="submit"][value="..."] selector generation for submit buttons that use value attribute instead of inner text

Changed

  • Fuzzy Matcher: Now breaks early only when score >= 110 (exact text match on primary element), not at 95
  • Element Discovery: Enhanced to prefer visible interactive elements over hidden containers

Verified

  • SauceDemo Checkout: 12/12 steps pass autonomously
  • Resolution Performance: Average 5-10ms per semantic goal
  • Self-Healing: Correctly identifies shifted selectors on dynamic forms

Release v1.3.0

Choose a tag to compare

@godhiraj-code godhiraj-code released this 08 Jan 14:04
fa1e274

[1.3.0] - 2026-01-08

🌐 Phase 14.1: Multi-Browser Foundation

New Feature: Cross-Browser Support

  • Browser Adapter Pattern: New BrowserAdapter architecture supporting Chromium, Firefox, and WebKit
  • Mission Control Integration: Browser selector dropdown in Hub card for one-click browser switching
  • Zero Protocol Changes: Sentinels remain 100% browser-agnostic (no breaking changes)

Performance Benchmarks:

  • Chromium: ~715ms startup
  • Firefox: ~1099ms startup
  • WebKit: ~545ms startup

Configuration:

{
  "hub": {
    "browser": {
      "engine": "chromium"  // or "firefox" or "webkit"
    }
  }
}

Browser Capabilities:

Browser Shadow DOM Piercing CDP Access Device Emulation
Chromium ✅ Full ✅ Full ✅ Full
Firefox ⚠️ Limited ❌ None ⚠️ Limited
WebKit ⚠️ Limited ❌ None ✅ Full (iOS)

🐛 Bug Fixes

  • Fixed deprecated datetime.utcnow() in A11ySentinel (Python 3.12+ compatible)

Release v1.2.2

Choose a tag to compare

@godhiraj-code godhiraj-code released this 07 Jan 16:42

All notable changes to the Starlight Protocol.

[1.2.2] - 2026-01-07

⚡ Protocol Robustness

  • Strict Compliance: Fixed Hub broadcastToClients to strictly adhere to JSON-RPC 2.0 (using method instead of type).
  • SDK Update: Updated IntentRunner (JS SDK) to support strict JSON-RPC structure while maintaining backward compatibility.

🛡️ Sentinel Intelligence (Janitor)

  • Zero False Positives: Implemented Intelligent Filter for starlight.pre_check. Now ignores non-blocking elements (Inputs, Selects) even if they have generic IDs like #newsletter.
  • Smart Remediation: Refined Size Heuristics to exempt known obstacles (e.g., CAPTCHAs) from size checks, ensuring critical blockers are never ignored.
  • Null Safety: Patched a critical crash where inputType: null from Hub metadata caused Sentinel failure.

✅ Certification

  • TCK Certified: Passed Official TCK Validator (6/6 Tests) for Protocol Compliance.
  • Regression Verified: Validated Core Integration, File Uploads, and Event Signaling.

v1.2.0 - Universal Protocol: Learning Persistence & Extended Commands

Choose a tag to compare

@godhiraj-code godhiraj-code released this 07 Jan 11:59
58839f4

🌟 Highlights

The Starlight Protocol now learns from every mission. Successfully resolved semantic goals are saved to 

starlight_memory.json
 and automatically reused for self-healing in future runs. The Hub becomes smarter with every execution.

Read more

v1.1.0 - A11y Sentinel: WCAG 2.1 AA Accessibility Auditing

Choose a tag to compare

@godhiraj-code godhiraj-code released this 04 Jan 06:13

🎉 Starlight Protocol v1.1.0

♿ A11y Sentinel - Accessibility Auditing

This release introduces the A11y Sentinel, a passive observer that performs WCAG 2.1 AA compliance audits during test execution without blocking automation flow.

✨ New Features

  • A11y Sentinel - Non-blocking accessibility auditor
  • 8 WCAG Rules implemented:
    • color-contrast (1.4.3) - Text contrast ratio checking
    • image-alt (1.1.1) - Image alt attribute validation
    • form-labels (1.3.1) - Form input labeling
    • heading-order (1.3.1) - Heading hierarchy validation
    • link-name (2.4.4) - Link purpose accessibility
    • button-name (4.1.2) - Button accessible names
    • focus-visible (2.4.7) - Focus indicator presence
    • aria-valid (4.1.2) - ARIA attribute validation

📊 Report Dashboard

The mission report now includes an Accessibility Audit section:

  • Score percentage with visual indicator
  • Level grading (A/B/C/D)
  • Violations grouped by category
  • Issue counts per rule type

🔧 Hub Integration

  • DOM snapshot collection for accessibility Sentinels
  • starlight.context_update for A11y report injection
  • SVG className handling fix

📋 Protocol Compliance

  • ✅ TCK Validator: 6/6 tests passed
  • ✅ Certified: Starlight Protocol v1.0.0 Compliant