Skip to content

Releases: stringsofthemind-oss/once

Once SDK 0.1.22

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 30 Sep 22:55
9ffb70b

What's Changed

Full Changelog: v0.1.21...v0.1.22

Once SDK 0.1.21

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 30 Sep 21:44
4712838

What's Changed

Full Changelog: v0.1.20...v0.1.21

Once SDK 0.1.20

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 30 Sep 15:07
8c0adf9

Phase 17 — reviewed semantics to runnable protection

This release shortens the path from a detected consequential local operation to a developer-reviewed, runnable protected integration.

Highlights

  • candidate-specific Doctor/manual fallback hands off to once review-local
  • durable reviewed-semantics artifact separates observations from developer-approved semantics
  • stable logical identity remains an explicit developer decision
  • complete effect-bearing payload remains an explicit developer decision
  • deterministic preview of the reviewed .mjs protection companion
  • explicit write-once materialization under .once/generated
  • stale source/review state fails closed
  • generated companion uses existing protectLocal execution semantics
  • permanent Node 24.15 CI proof exercises the materialized companion across fresh processes

Proven behavior

  • first logical execution performs one effect
  • same identity + same payload replays without another effect
  • same identity + changed effect-bearing payload returns CONFLICT
  • response loss after commit becomes UNKNOWN
  • retry of UNKNOWN does not blindly redispatch

Safety boundaries unchanged

  • no inferred business identity
  • no inferred complete effect-bearing payload semantics
  • no UNKNOWN -> execute
  • no unresolved-claim bypass
  • no Authorization preservation
  • no silent application source/call-site rewrite
  • same-machine Node 24.15+ durability boundary remains explicit
  • no universal exactly-once claim

Release source:

8c0adf9

Once SDK 0.1.19

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 30 Sep 03:18
6b30fa3

Once SDK 0.1.19

Phase 16G cold-user-driven usability release.

Highlights

  • Adds candidate-specific, review-only protectLocal fallback guidance after safe automatic refusal.
  • Uses the existing .once/protect-plan.json decision rather than introducing a parallel eligibility engine.
  • Surfaces observed local inputs as source observations without claiming they define logical identity or complete effect-bearing payload.
  • Generated id and payload callbacks deliberately remain non-runnable until reviewed.
  • Adds a controlled verification recipe covering duplicate replay/suppression, payload conflict, ambiguous UNKNOWN handling, reconciliation, and durable same-machine state.
  • Pins the CU#5-style HTTP_WRITE local-function experience in regression coverage.

Safety boundaries unchanged

  • No transformer widening.
  • No new auto-apply eligibility.
  • No inferred provider mapping.
  • No inferred business identity.
  • No automatic payload-semantic inference.
  • No source mutation from manual guidance.
  • No UNKNOWN -> execute behavior.
  • No Authorization preservation into protected actions.
  • No universal exactly-once claim.

Release source:
6b30fa3fde08e937cc906d37353bc3ce55b1c304

Once SDK 0.1.14

Choose a tag to compare

@github-actions github-actions released this 28 Sep 20:43
1292d2c

Once SDK 0.1.14

This GitHub Release aligns the repository release page with the already-published @once-agent/sdk@0.1.14 package.

Release source commit: 1292d2c70c737adcd68c8f83e7a72ef5b30fc354.

Highlights

  • Includes the SDK release state through the Phase 13C persistent MCP/replay work present at the frozen 0.1.14 release commit.
  • Preserves conservative execution-safety behavior: stable logical operation identity, fail-closed ambiguity, durable replay, and provider reconciliation boundaries.
  • No universal exactly-once claim is made.

Distribution note

This action does not republish npm packages. It creates the missing GitHub release/tag for the already-published SDK version. The current MCP package is @once-agent/mcp@0.1.5.

Once SDK 0.1.12

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 25 Sep 15:22
636c7f1

Once SDK 0.1.12

Once 0.1.12 ships the completed Phase 11 tool-discovery and selective Gateway work.

Highlights

  • Automatic Connect tool classification and whole-toolset protection wiring.
  • once doctor . --tools Tool Graph discovery and I0-I5 importance scoring.
  • Explicit authoritative MCP tools/list discovery and bounded refresh.
  • Runtime/model-visible discovery across major agent frameworks.
  • Execution observation with secret-minimal EXECUTED evidence.
  • Selective Gateway DIRECT / PROTECT / BLOCK routing.
  • Structural OpenAI Agents FunctionTool integration.
  • Public @once-agent/sdk/connect, /discovery, and /gateway package surfaces.

Safety

  • UNKNOWN and unresolved consequential operations fail closed.
  • Tool Graph evidence cannot downgrade a required PROTECT route.
  • Transport/tool-call IDs remain separate from logical Once operation identity.
  • Ambiguous outcomes do not become permission to repeat an external effect.
  • No universal exactly-once claim is made.

Validation

The exact release contents passed:

  • full TypeScript SDK release suite
  • SDK safety regressions
  • Python safety regressions
  • Worker and MCP regressions
  • Node.js 24.15 packed Connect protected-execution proof
  • Node.js 24.15 packed Gateway protected-execution proof
  • isolated publishable-tarball consumer tests

Once SDK 0.1.11

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 25 Sep 03:20
750472e

Adds a registered agent-tool connection for the local Once protection boundary. Agents call the connected tool normally; retries reuse confirmed outcomes, changed payloads conflict, and uncertain outcomes require provider truth. Requires Node.js 24.15+ and shared durable SQLite state on one machine.

Once SDK 0.1.10

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 25 Sep 01:58
ced646b

Protect now explains the safe next steps for adapter-required operations: a controlled local proof versus a real provider integration. Automatic rewriting remains unavailable for those callsites.

Once SDK 0.1.9

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 25 Sep 01:23
c14be99

Once Doctor now prints runnable, package-qualified follow-up commands when used in a fresh project. This patch improves the CLI adoption flow; it does not change the execution-safety model.

Once SDK 0.1.8

Choose a tag to compare

@stringsofthemind-oss stringsofthemind-oss released this 25 Sep 00:44
85715d2

Once SDK 0.1.8 makes once doctor the adoption front door.

What's new

  • once doctor [directory] now runs as a local, read-only first step.
  • No ONCE_API_KEY is required for the default Doctor scan.
  • Source code is not uploaded and application source is not modified.
  • Doctor reports detected project tooling and likely consequential-operation candidates.
  • Doctor prints the four-condition Once qualification test and the exact next once protect command.
  • once doctor . --protect generates a review plan and per-callsite snippets without rewriting source.
  • once doctor . --connection explicitly verifies the hosted Once connection and requires ONCE_API_KEY.
  • Doctor adoption regression is included in the SDK release test suite.

Safety

The existing conservative protection boundaries remain unchanged:

  • ambiguous outcomes fail closed
  • changed effect-bearing payloads conflict rather than silently re-execute
  • protect --apply remains a separate explicit mutation step
  • unsupported or unsafe transformations are rejected rather than guessed

Runtime requirements

  • General SDK: Node.js 18+
  • protectLocal: Node.js 24.15+

npm

@once-agent/sdk@0.1.8