Releases: stringsofthemind-oss/once
Release list
Once SDK 0.1.22
What's Changed
- Add GitHub lost-ack recovery without retained issue numbers by @stringsofthemind-oss in #258
- Release SDK 0.1.22 by @stringsofthemind-oss in #265
Full Changelog: v0.1.21...v0.1.22
Once SDK 0.1.21
What's Changed
- Pin capability contract for response-preserving HTTP autoprotection by @stringsofthemind-oss in #218
- Add capability-gated HTTP JSON response consumption transformer by @stringsofthemind-oss in #219
- Bind and patch capability-gated HTTP JSON response consumption by @stringsofthemind-oss in #220
- Promote proven HTTP autoprotection coverage to 7 of 15 by @stringsofthemind-oss in #221
- Prove packed consumer path for HTTP JSON autoprotection by @stringsofthemind-oss in #222
- Pin generic HTTP BodyInit normalization contract by @stringsofthemind-oss in #224
- Pin client action contract for BodyInit HTTP writes by @stringsofthemind-oss in #226
- Pin worker reconstruction contract for BodyInit HTTP writes by @stringsofthemind-oss in #227
- Pin HTTP response replay v2 native contract by @stringsofthemind-oss in #230
- Persist exact HTTP response replay v2 receipts by @stringsofthemind-oss in #232
- Expose native HTTP Response replay v2 in the SDK by @stringsofthemind-oss in #233
- Prove capability-gated assigned native Response preservation by @stringsofthemind-oss in #234
- Prove capability-gated returned native Response preservation by @stringsofthemind-oss in #235
- Integrate native Response protect/apply planning by @stringsofthemind-oss in #236
- Promote HTTP autoprotection benchmark to 9/15 by @stringsofthemind-oss in #237
- Phase 18 slice 1 — read-only caller inventory by @stringsofthemind-oss in #239
- Phase 18 slice 2 — deterministic routing preview by @stringsofthemind-oss in #240
- Phase 18 slice 3 — explicit routing review by @stringsofthemind-oss in #241
- Phase 18 slice 4 — stale-source transactional routing apply by @stringsofthemind-oss in #243
- Phase 18 slice 5 — active routed application proof by @stringsofthemind-oss in #244
- Prepare SDK 0.1.21 release candidate by @stringsofthemind-oss in #245
Full Changelog: v0.1.20...v0.1.21
Once SDK 0.1.20
Phase 17 — reviewed semantics to runnable protection
This release shortens the path from a detected consequential local operation to a developer-reviewed, runnable protected integration.
Highlights
- candidate-specific Doctor/manual fallback hands off to
once review-local - durable reviewed-semantics artifact separates observations from developer-approved semantics
- stable logical identity remains an explicit developer decision
- complete effect-bearing payload remains an explicit developer decision
- deterministic preview of the reviewed
.mjsprotection companion - explicit write-once materialization under
.once/generated - stale source/review state fails closed
- generated companion uses existing
protectLocalexecution semantics - permanent Node 24.15 CI proof exercises the materialized companion across fresh processes
Proven behavior
- first logical execution performs one effect
- same identity + same payload replays without another effect
- same identity + changed effect-bearing payload returns
CONFLICT - response loss after commit becomes
UNKNOWN - retry of UNKNOWN does not blindly redispatch
Safety boundaries unchanged
- no inferred business identity
- no inferred complete effect-bearing payload semantics
- no UNKNOWN -> execute
- no unresolved-claim bypass
- no Authorization preservation
- no silent application source/call-site rewrite
- same-machine Node 24.15+ durability boundary remains explicit
- no universal exactly-once claim
Release source:
Once SDK 0.1.19
Once SDK 0.1.19
Phase 16G cold-user-driven usability release.
Highlights
- Adds candidate-specific, review-only
protectLocalfallback guidance after safe automatic refusal. - Uses the existing
.once/protect-plan.jsondecision rather than introducing a parallel eligibility engine. - Surfaces observed local inputs as source observations without claiming they define logical identity or complete effect-bearing payload.
- Generated
idandpayloadcallbacks deliberately remain non-runnable until reviewed. - Adds a controlled verification recipe covering duplicate replay/suppression, payload conflict, ambiguous UNKNOWN handling, reconciliation, and durable same-machine state.
- Pins the CU#5-style HTTP_WRITE local-function experience in regression coverage.
Safety boundaries unchanged
- No transformer widening.
- No new auto-apply eligibility.
- No inferred provider mapping.
- No inferred business identity.
- No automatic payload-semantic inference.
- No source mutation from manual guidance.
- No UNKNOWN -> execute behavior.
- No Authorization preservation into protected actions.
- No universal exactly-once claim.
Release source:
6b30fa3fde08e937cc906d37353bc3ce55b1c304
Once SDK 0.1.14
Once SDK 0.1.14
This GitHub Release aligns the repository release page with the already-published @once-agent/sdk@0.1.14 package.
Release source commit: 1292d2c70c737adcd68c8f83e7a72ef5b30fc354.
Highlights
- Includes the SDK release state through the Phase 13C persistent MCP/replay work present at the frozen 0.1.14 release commit.
- Preserves conservative execution-safety behavior: stable logical operation identity, fail-closed ambiguity, durable replay, and provider reconciliation boundaries.
- No universal exactly-once claim is made.
Distribution note
This action does not republish npm packages. It creates the missing GitHub release/tag for the already-published SDK version. The current MCP package is @once-agent/mcp@0.1.5.
Once SDK 0.1.12
Once SDK 0.1.12
Once 0.1.12 ships the completed Phase 11 tool-discovery and selective Gateway work.
Highlights
- Automatic Connect tool classification and whole-toolset protection wiring.
once doctor . --toolsTool Graph discovery and I0-I5 importance scoring.- Explicit authoritative MCP
tools/listdiscovery and bounded refresh. - Runtime/model-visible discovery across major agent frameworks.
- Execution observation with secret-minimal EXECUTED evidence.
- Selective Gateway DIRECT / PROTECT / BLOCK routing.
- Structural OpenAI Agents FunctionTool integration.
- Public
@once-agent/sdk/connect,/discovery, and/gatewaypackage surfaces.
Safety
- UNKNOWN and unresolved consequential operations fail closed.
- Tool Graph evidence cannot downgrade a required PROTECT route.
- Transport/tool-call IDs remain separate from logical Once operation identity.
- Ambiguous outcomes do not become permission to repeat an external effect.
- No universal exactly-once claim is made.
Validation
The exact release contents passed:
- full TypeScript SDK release suite
- SDK safety regressions
- Python safety regressions
- Worker and MCP regressions
- Node.js 24.15 packed Connect protected-execution proof
- Node.js 24.15 packed Gateway protected-execution proof
- isolated publishable-tarball consumer tests
Once SDK 0.1.11
Adds a registered agent-tool connection for the local Once protection boundary. Agents call the connected tool normally; retries reuse confirmed outcomes, changed payloads conflict, and uncertain outcomes require provider truth. Requires Node.js 24.15+ and shared durable SQLite state on one machine.
Once SDK 0.1.10
Protect now explains the safe next steps for adapter-required operations: a controlled local proof versus a real provider integration. Automatic rewriting remains unavailable for those callsites.
Once SDK 0.1.9
Once Doctor now prints runnable, package-qualified follow-up commands when used in a fresh project. This patch improves the CLI adoption flow; it does not change the execution-safety model.
Once SDK 0.1.8
Once SDK 0.1.8 makes once doctor the adoption front door.
What's new
once doctor [directory]now runs as a local, read-only first step.- No
ONCE_API_KEYis required for the default Doctor scan. - Source code is not uploaded and application source is not modified.
- Doctor reports detected project tooling and likely consequential-operation candidates.
- Doctor prints the four-condition Once qualification test and the exact next
once protectcommand. once doctor . --protectgenerates a review plan and per-callsite snippets without rewriting source.once doctor . --connectionexplicitly verifies the hosted Once connection and requiresONCE_API_KEY.- Doctor adoption regression is included in the SDK release test suite.
Safety
The existing conservative protection boundaries remain unchanged:
- ambiguous outcomes fail closed
- changed effect-bearing payloads conflict rather than silently re-execute
protect --applyremains a separate explicit mutation step- unsupported or unsafe transformations are rejected rather than guessed
Runtime requirements
- General SDK: Node.js 18+
protectLocal: Node.js 24.15+
npm
@once-agent/sdk@0.1.8