Releases: swisspra/Pursers
Release list
Pursers 5.0.8
This release includes pursers-central==0.1.5,
pursers-client==0.1.6, pursers-personal-import==5.0.0,
pursers-personal==5.0.8, pursers==5.0.8,
pursers-wait-bridge==0.1.4, and
pursers-acp==0.1.5.
5.0.8 ships everything listed under 5.0.7. The v5.0.7 tag was never published
to PyPI apart from pursers-wait-bridge==0.1.4: its pursers-acp wheel kept
version 0.1.4 while its dependency pins moved to the 5.0.7 cohort, so the
publish verifier refused bytes that differed from the 0.1.4 already on PyPI.
Fixed
pursers-acpis versioned 0.1.5 so it installs alongside the rest of the
cohort (pursers-client==0.1.6,pursers-personal==5.0.8,
pursers-wait-bridge==0.1.4).
Pursers 5.0.7
This release includes pursers-central==0.1.5,
pursers-client==0.1.6, pursers-personal-import==5.0.0,
pursers-personal==5.0.7, pursers==5.0.7,
pursers-wait-bridge==0.1.4, and
pursers-acp==0.1.4.
Added
- Board Butler can own seat management on a host: a single operator-set host
seat cap (set_host_seat_capButler command, bound to the authorization
envelope) authorizes Butler to start, stop, pause, and re-role worker and
reviewer seats within the cap through a persisted canonical roster. Re-role
refuses a target whose principal is already active on another seat before
any host action, and every mutation binds identity, state, and roster
revision. - Board Butler connectors accept several secret headers per MCP endpoint
(for header-gated servers), bounded static headers, a--connector-config
runtime file with file-referenced secrets, and a--connector-probethat
reports tool-set drift without printing secrets. - Generic source-aware intake: any MCP source is declared in configuration
(SonarQube first) and becomes deduplicated, routed intake asks with
source text kept in a bounded untrusted block and optional writeback. - Board Butler can onboard a project it has not seen before: it resolves the
repository, clones the project folder, and registers it, with capped retry
and backoff that survive restarts. - Boards can set a default ticket tier (
board_dispatch_policy_setwith
default_ticket_tier). A ticket created without an explicit tier takes the
board default, explicit tiers still win, and boards without the setting keep
tier 2. The client no longer sends tier 2 when the caller omits it.
Fixed
- The Fleet release card probes the configured Central URL and derives its
health endpoint from that origin instead of the plain-HTTP default. - A Board Butler test no longer depends on the checkout having a local main
ref, so pull-request CI runs pass. - Board Butler moves the approved-but-not-landed scan off its hot refresh loop
and reuses cached findings, so a large board no longer slows every refresh. - The rollout runbook and read-only rollout doctor handle the defects found in
the live 5.0.6 rollout: third-party dependency resolution for offline
installs, Central upgrades with pinned clients, the Fleet environment
contract, Butler fleet preflight,./-prefixed checksum rows, editable
freeze constraints, and collector-based digest freshness.
Changed
- The Home runtime wheelhouse lock is refreshed for Linux x86_64 and macOS
arm64 (PyJWT 2.15.1, sse-starlette 3.5.0).
Documentation
- The rollout runbook documents the Linux/systemd path and a version-neutral
host layout: persistent data in one stable service tree, each release as a
side-by-side venv/assets/source tree, and upgrades that only repoint the
unit's runtime paths.
Pursers 5.0.6
This release includes pursers-central==0.1.4,
pursers-client==0.1.5, pursers-personal-import==5.0.0,
pursers-personal==5.0.6, pursers==5.0.6,
pursers-wait-bridge==0.1.3, and
pursers-acp==0.1.4.
Added
- Fleet Dashboard has a new visual shell with self-hosted typography, shared
design tokens, a clearer page frame, and navigation that shows the active
route, data freshness, and connection state at a glance. Legacy hash links,
theme and density controls, shortcuts, and focus order are unchanged. - Every primary Fleet route is redesigned around the question an operator is
asking. Home leads with team health, human attention, and the next action.
Work reads as a ledger with ticket detail, timeline, and review handoff.
Team cards show status, role, model, tier, and current work. Approvals puts
pending human decisions and review status first and states the consequence
before each action. Activity is a source-backed timeline with provenance.
Projects clarifies health and ownership. Settings groups existing controls
by task and risk. - Fleet route modules own their renderers and may load allowlisted
route-owned stylesheets through a single safe asset loader. - Board Butler can merge an approved submission in autonomous mode when the
active configuration explicitly authorizes it. The merge is bound to the
exact approved commit, which must be reachable in the configured
repository. Configurations created before this authority existed cannot
inherit it. - macOS fleet execution provisions per-seat launchd services through a narrow
per-user adapter with no shell command surface. - Design contracts for Fleet public display, ticket progress checkpoints,
seat and project lifecycle, and a controlled sequential-versus-parallel case
study, plus a documented 5.0.5 visual baseline. - Workers can persist bounded progress assessments with a completion range,
confidence, evidence, and revision fencing without renewing their lease. - Fleet Seats can generate digest-bound cross-board role configurations and a
copyable setup bundle for applying them safely. - Fleet Work shows bounded progress, lease time remaining, and assessment
freshness from source-backed ticket state. - Fleet Team reports source-backed model usage and cost attribution, while
unsafe aggregate inputs fail closed. - Fleet public display mode exposes a read-only, privacy-bounded projection
with safe aliases and suppresses mixed-cohort alias collisions. - Board Butler observes Fleet flow signals, including mature-board approval
state. - The autonomous Fleet path has an end-to-end acceptance proof across the
current board scope. - A validated, redaction-audited Fleet public media pack provides screenshots,
a storyboard, and a machine-readable manifest. - The
pursers-registrycommand bootstrapsproject_registryon a fresh
installation. - Fleet Projects supports guarded project add and remove operations.
- Fleet credentials guides door credential issue, rotation, and revocation.
- The 5.0.6 rollout runbook includes a read-only rollout doctor and explicit
post-rollout verification checks.
Changed
- Fleet UI assets are packaged as files instead of inline HTML, and the
integration manifest tracks the new route assets. - The Fleet autonomous view no longer labels a desired or authorized
configuration as active until a fresh, matching runtime state is observed. - The Butler Active control accepts the guarded
answering_modesetting.
Fixed
- The five-second Fleet refresh no longer resets scroll position, focus,
disclosures, or in-progress reading. Network reads continue while a form is
being edited, and clean Butler controls accept refreshed server data. - Wait Bridge and client event subscriptions reconnect when an MCP error wraps
a transport failure. Previously the subscription could stay disconnected and
report push as unavailable. - The CI manifest's live-authority check uses one takeover mode and rejects a
Central session authenticated as the wrong board, agent, role, or principal. - Typed MCP ticket errors retain their safe structured detail through the
client and Personal dashboard instead of being reduced to a generic error. - Fleet executor readiness and seat-kit checks recognize valid generated Goose
seats while continuing to reject incomplete capability metadata. - Registry administration honors each registry's configured home board, and
onboarding tolerates a pinned memory entry whose optional content is absent. - Fleet interactive links meet the 44-pixel touch-target requirement, the
keyboard-help dialog traps and restores focus, and completed search
navigation clears its query state. - Fleet Team uses source-backed host mode to distinguish ACP sessions from
persistent seats instead of inferring lifecycle from host names. - Board Butler no longer exits on an optimistic board-state conflict; the
question is deferred and replayed with fresh state. - Fleet and Board Butler launch templates share explicit runtime, PID, kill,
and provider-secret paths so their process controls use the same contract. - The stranded-approvals audit pages oversized ticket statuses safely and
reuses its reserved audit identity without taking over a live seat. - Explicit token files take precedence over inherited environment tokens;
empty explicit files are rejected and startup configuration failures remain
visible for recovery. - Fleet project lifecycle conflicts return HTTP 409 on every platform instead
of 501 on hosts without the macOS worker manager. - The PyPI publishing workflow accepts the v5.0.6 stable tag.
Security
- launchd provisioning and restarts fail closed on plist identity mismatches,
loaded-template drift, unavailable plists, symlinked or non-owner-only
directories, and invalid fields. - Approved-merge automation fails closed when the ticket is unreadable, the
approved commit is unavailable, or the configuration does not grant merge
authority. Production and pull-request merge rules remain escalation-first. - Strict review rechecks that reviewer and submitter principals are independent
when a review lease is renewed.
Pursers 5.0.5
This release includes pursers-central==0.1.3,
pursers-client==0.1.4, pursers-personal-import==5.0.0,
pursers-personal==5.0.5, pursers==5.0.5,
pursers-wait-bridge==0.1.2, and
pursers-acp==0.1.3.
Added
- Board Butler can now run a policy-gated autonomous loop. Versioned command,
configuration, audit, executor, state, and model contracts connect bounded
board observations to least-privilege MCP connectors, typed host actions,
pluggable model runners, durable replay protection, and explicit operator
holds and vetoes. - Fleet Dashboard adds accessible Autonomous Butler controls and actual-state
reporting. Desired state is reconciled across the active WORK registry, and
displayed state remains tied to the configuration revision that produced it. - Fleet execution now has a typed, fail-closed host boundary with policy
generation fences, cumulative approved-batch scope, registry-wide seat
discovery, and separate worker and reviewer readiness checks. - CI adds an affected-suite selector and a single repository batch gate. Normal
changes run focused tests plus the affected manifest, while high-risk and
release-train work still runs the complete 14-suite manifest.
Changed
- Board Butler's active path now supports guarded coordinator-question answers,
OpenAI chat-compatible providers, sandboxed ACP model processes, bounded
execution time, and validated persisted results without granting model
clients board or host tools. - Registry routing carries the exact project board through questions, offers,
ACP dispatch, and fleet reconciliation. Worker and reviewer availability is
explicit, incomplete seat inventories are retried, and live board authority
is required before CI-backed fleet actions proceed. - Clients bind authenticated sessions to a stable Central instance identity so
cached cursors, watches, and credentials fail closed instead of crossing a
replaced service instance. - Seat and systemd diagnostics now distinguish configuration, manager,
resource, status, and execution failures; verify the effective executable;
accept canonical unit paths; and keep unsupported host tests from masquerading
as product failures. - Generated CLI and MCP references, integration manifests, delivery metadata,
and operator guidance now describe the autonomous controls, readiness model,
validation policy, and recovery paths shipped in this cohort.
Fixed
- Wait Bridge no longer loses registry-home routing, structured deferred-wait
failures, or connection accounting across multi-board subscriptions. It also
keeps claimable work and complete seat inventories reconciled without opening
duplicate journal connections. - Board Butler survives subscription authorization races and a full findings
buffer, preserves the originating board for questions, routes multi-board
tickets correctly, migrates state across policy changes, and rejects stale
policy revisions, replayed commands, and mismatched configuration state. - Fleet and seat administration now preserve human access to escalated
questions, authorize reviewer readiness correctly, report real systemd
failures precisely, quote unit paths safely, and reuse registry clients
sequentially without leaking prior connection state. - Zed ACP reports deferred wait failures as structured errors, while Fleet
selectors, autonomous controls, and state projections retain their contract
and accessibility behavior during live refreshes.
Security
- Code submissions carry repository-bound proof through the authenticated
client, preventing a valid-looking but unreachable, stale, wrong-branch, or
local-only commit from being accepted as reviewable source. - MCP connectors reject encoded responses, mutable argument snapshots, and
non-boolean policy decisions. Model-provider references and subscription
diagnostics are scrubbed so credentials and URI user information cannot
enter results or logs.
Pursers 5.0.4
This release includes pursers-central==0.1.2,
pursers-client==0.1.3, pursers-personal-import==5.0.0,
pursers-personal==5.0.4, pursers==5.0.4,
pursers-wait-bridge==0.1.1, and
pursers-acp==0.1.2.
Added
- Zed:
/setupnow provisions a local Central, creates or joins the configured
board, and refreshes the real board tools in the same chat after explicit
confirmation. The managed identity is supplied automatically, so the first
/createdoes not require an internal agent name. A new end-to-end guide
follows one ticket from installation through an independent approval. - Zed: when no system
uvxis available, the extension downloads the matching
uvrelease asset, verifies its published SHA-256 checksum, caches it in the
extension's private directory, and launches the resolved absolute executable.
An explicituvx_pathremains available for operator-managed installations. - Board Butler: add a bounded, read-only Board Observer that carries held
decisions forward, reconciles explicitly linked open questions, reports
repeated standing decisions and scope drift, and fails closed when its board
projection is incomplete. Shadow and active modes observe identically; this
adds no new autonomous action class. - Operations: add a fail-closed temporary-root janitor for abandoned Pursers
test directories. It checks age, owner processes, locks, open files,
environment references, and working directories before quarantining and
deleting an exact root. CI now refuses to start with less than 10 GB free
instead of failing later with a misleading test error.
Changed
- Zed: local setup accepts only an absolute
setup_root, refuses unrelated or
incomplete directories, and reports the exact reusable layout it expects.
Connections to an existing Central can create or join a missing board after
confirmation and can reuse the authenticated principal's single active seat;
ambiguous identities are listed instead of guessed. - Zed documentation now distinguishes native Zed Agent threads, where MCP
context servers are available, from external ACP-agent threads, where the
extension is intentionally absent. It also records the Configure dialog's
replacement behavior, uninstall cleanup, Restricted Mode, and the supported
recovery paths observed in real installs. - Release publishing now builds and verifies the complete seven-wheel cohort
before upload, including filenames, wheel generators, embedded component-lock
digests, dependency pins, and already-published artifact bytes. - Board Butler's operator guide now documents shadow behavior, bounded findings,
the active-mode authorization and hold/veto controls, registry-wide refresh,
service status, and the fail-closed emergency stop.
Fixed
- Zed now launches the context server through a verified absolute executable
path. A bareuvxcould pass the probe but still fail when Zed spawned it,
leaving only a broken-pipe error. - Zed's packaged extension and runtime consumers now pin the current client
cohort, avoiding installation of a one-release-old client. - Worker waits periodically reconcile current claimable state with the journal,
so an offer or broadcast that predates the subscription still reaches an idle
seat. Permanently unsafe repository routes remain filtered, while a clone that
has not appeared yet remains retryable. - Seat administration can reuse the same authenticated principal after an
interrupted or stale onboarding attempt instead of rejecting the existing
seat name, while retaining the board's takeover checks. - Worker startup reports invalid configuration and permission failures as
concise configuration errors instead of uncaught tracebacks.
Pursers 5.0.3
This release includes pursers-central==0.1.1,
pursers-client==0.1.2, pursers-personal-import==5.0.0,
pursers-personal==5.0.3, pursers==5.0.3,
pursers-wait-bridge==0.1.0, and
pursers-acp==0.1.1.
Added
- Zed: a seat's question now reaches you and can be answered where you are.
/watchends its turn when a question arrives, which is what lets Zed's own
completion notification wake you; we add no notification of our own because
Zed gives an idle thread none./answerthen opens a form for the question,
so you never retype a ticket ID, and/answer #2picks between several.
Declining the form, cancelling it, refusing the permission prompt or closing
the thread all leave the question unanswered on the board. The write still
goes through Zed's permission prompt: answering a seat is a write. - Zed: the plan says who holds each ticket and what it waits on, ordered by
what needs a human first, then review, then work, then queued. Priorities
mean something rather than all being high, an idle board says it is quiet,
and a write is announced by what it does instead of by the tool that does it. - Zed: a board running several projects is legible as several projects. The
plan groups what is in flight, anddocs/zed/multi-project.mdshows it. - Zed: the five commands read like product rather than instructions to a model.
Zed prints a prompt's body in the thread before any answer arrives, so those
five strings are the most-read copy the extension has; they used to name our
tools and arguments. A board summary can also no longer disagree with itself:
the counts are board-wide and the list below them says it is a subset. - Zed:
/watchnow shows the fleet's work as a live plan. One entry per ticket
in flight, refreshed from the subscription that already exists, so a human
watching twelve seats can read what is moving. The entry count is bounded and
says so when it overflows; a ticket in review is never shown as completed,
because ACP has no status that means "waiting on a reviewer". An idle board
still shows one entry, so quiet reads as quiet rather than as broken. - Zed: the guide shows what the integration looks like. Six screenshots taken
through an isolated profile against a throwaway board, each placed at the
step it illustrates. - Zed: the guide now covers Restricted Mode. Zed opens an unfamiliar project
with every MCP server blocked and no log line to explain it, so Pursers shows
no state dot and no commands until Trust and Continue is clicked. docs/zed/research/08-surface-audit.mdrecords what Zed 1.20.2 actually
gives an integration, with a citation per row. The finding that shaped this
release: an ACPsession/updatereaches a thread with no prompt in flight,
but raises no notification by itself. Zed notifies on the thread'sStopped
event, so ending the turn is the notification. An MCP context server has no
equivalent channel at all.
Fixed
release_trainno longer moves a version that belongs to another component.
In a line such asbridge=0.1.0 client=0.1.0, the pattern that matches a bare
version followed by a package name claimed the bridge's version for the
client. A version already bound to a name on its left is now left alone, and
pursers-wait-bridgegained the short aliasbridgeit was the only
component to lack.- The wait-bridge test suite cleans up the temporary key directory it has to
create before importing the module under test. Every run used to leave one
behind.
Pursers 5.0.2
This release includes pursers-central==0.1.1,
pursers-client==0.1.1, pursers-personal-import==5.0.0,
pursers-personal==5.0.2, pursers==5.0.2,
pursers-wait-bridge==0.1.0, and
pursers-acp==0.1.0.
Added
- Zed: run a Pursers board from Zed's Agent Panel.
pursers-clientships a new
pursers-mcpstdio MCP server that relays to Central, reads its credential
from a token file (re-read after an issuer-key rotation), speaks the MCP
revision Zed negotiates, exposes a curated tool set, and adds five prompts —
board,create,watch,evidence,answer. A Zed extension at
integrations/zed/pursers-mcplaunches it throughuvxand configures it in
Zed's native context-server modal. See Use Pursers from Zed. - MCP Registry:
server.jsonnow also lists thepursers-mcpstdio server, so
MCP clients can discover it alongside Central. - ACP:
pursers-acpadvertises the same five commands, reports configuration
and authentication problems as agent messages, and carries a prepared entry
for the ACP Registry. - Fleet:
seat-kit checkcatches seat identity drift (AGENTS.md vs START.md vs
folder) before a seat onboards under another seat's name. - Operator tooling:
tools/zed/e2e_isolated.pyproves the whole chain in an
isolated Zed profile;tools/zed/export_extension.pyand
tools/zed/check_registry.pyproduce and validate the registry submission. - Research:
docs/zed/research/01–07— Zed's extension API, context servers,
ACP, UI limits and UX design, publishing rules, prior art, and the AI
landscape including Zed's Delta.
Pursers 5.0.1
This release includes pursers-central==0.1.1,
pursers-client==0.1.0, pursers-personal-import==5.0.0,
pursers-personal==5.0.1, pursers==5.0.1,
pursers-wait-bridge==0.1.0, and
pursers-acp==0.1.0.
Added
- Central: add
pursers-central rotate-keyandpursers-central retire-key
for zero-downtime issuer key rotation.rotate-keypublishes a new signing
key next to the old one and re-signs the given token files in place,
including multi-header files such asmcp-remote --header-fileinputs;
retire-keyremoves the old key only after every--check-tokenfile
verifies against the new one. Central re-reads the JWKS on every request, so
neither step needs a restart. - Documentation: add the Add agents, Connect your MCP client, Run a
multi-agent fleet, Operate Central, Fleet dashboard and Board Butler,
Security, and Troubleshooting guides, the issuer key rotation manual, and
generated MCP tool, CLI, and environment references that tests keep in step
with the code. - README: rebuild it as a landing page with the recorded ticket-flow and
wake-don't-poll demos, an animated ticket lifecycle in light and dark
variants, and measured prompt-cache efficiency.
Fixed
- Fleet dashboard: report the running revision even when the machine is under
heavy load, instead of returningnullwhengitis slow. - Release workflow: publish
pursers-acpin its own step so a failed upload
of that package cannot stop the pinned dependencies from reaching PyPI.
Pursers 5.0.0
This release includes pursers-central==0.1.0,
pursers-client==0.1.0, pursers-personal-import==5.0.0,
pursers-personal==5.0.0, pursers==5.0.0,
pursers-wait-bridge==0.1.0, and
pursers-acp==0.1.0.
Added
- Central: add
pursers-central initandpursers-central runas the packaged
newcomer path from a PyPI installation to private credentials, a local board,
and a running authenticated service. - ACP: publish
pursers-acp 0.1.0for ACP-capable IDEs and include it in the
coordinated release manifest. - Distribution: prepare the Central metadata and
server.jsonused for an MCP
Registry listing. - Release workflow: build and upload the AionUi extension ZIP and the locked
Home runtime wheelhouse alongside the Python distributions. - Central: support TLS certificate and key inputs plus a configurable HTTP Host
allowlist in the packaged runtime. - Fleet dashboard: add repository-owned launch and upgrade commands so the
operator service can follow an exact checkout instead of an untracked host
script. - Release checks: compare every approved ticket's content with
mainso an
approved but unmerged change blocks the release gate.
Changed
- Packaging:
pursers,pursers-personal, andpursers-personal-importare
classifiedDevelopment Status :: 5 - Production/Stable; every PyPI summary
uses the Pursers name, and the package READMEs document the real install
paths instead of pre-release installation gates. - Personal: the MCP App title and footer read
Pursers Personalinstead of
On Board Personal Preview. The MCP server name is unchanged, so existing
host configurations keep working. - Wait Bridge documentation records the measured AionUi 2.2.1 / AionCore
0.2.1 imported-stdio behavior: bounded waits used poll mode, native
elicitation was not rendered, and session delivery required the authenticated
MCP import API with transport fields nested undermcpServers[].transport.
Fixed
- Fleet dashboard: pages no longer jump while you read. The server serves the
last snapshot while one background refresh runs, so slow Central reads no
longer time out the 5-second page refresh, and the connection banner is an
overlay that takes no layout space. - Personal import: documented commands use the real
pursers-personal-import
console script.
Security
- Fleet dashboard: Board Butler provider validation refuses link-local targets,
including non-canonical numeric IPv4 forms and DNS names that resolve to
them, connects only to the validated address, and rejects cross-origin
redirects (CodeQLpy/full-ssrf). - Managed seat configuration and Wait Bridge child-process checks compare
token fingerprints instead of storing or forwarding raw JWTs.
Pursers 5.0.0b2
This release includes pursers-central==0.1.0a31,
pursers-client==0.1.0a24, pursers-personal-import==5.0.0a3,
pursers-personal==5.0.0b2, pursers==5.0.0b2, and
pursers-wait-bridge==0.1.0a17.
Changed
- Upgraded the Python MCP SDK pins across central, client, and personal from
2.1.1 to 2.2.0; CI now verifies the installed SDK version explicitly.
Fixed
- Seat kit tests: the synthetic door token used by the door tests now carries
a valid base64url signature segment. PyJWT 2.14.0 (2026-09-11) decodes the
signature segment even withverify_signature=False, so the former literal
synthetic-signaturefailed withInvalid crypto paddingand turned the
ciworkflow red on every push; production doors were never affected. - Wait bridge: the lease keepalive's discovery re-join on Codex hosts no longer
overwrites the seat's dispatch capabilities withcan_work=false, can_review=falsewhile the model is live (insidea2a_waitor within the
idle limit). Only a truly idle Codex seat stops advertising capability. The
old behaviour made every Codex seat flap between eligible and
no_eligible_worker/no_eligible_revieweron each keepalive tick, so
Central revoked offers seconds after issuing them. - Wait bridge and client: a
board_joinrefused as an authorization decision
(invite required,lacks board:<scope>,board role not authorized) is
now cached for 900 s instead of being retried on every wait cycle, cue, and
reconnect. One misconfigured Claude Desktop seat (PURSERS_ROLE=orchestrator
with a token lackingboard:coordinate) and worker seats whose principal was
invited to one board only had issued more than 17,000 refused joins against
Central in two days. The bridge classifies these refusals asdenied, sleeps
the subscriber for the same window after a permanent home-board failure, and
_registry_boardshonorsPURSERS_BOARDS(registry|home| list) so a
seat no longer joins every registry board its credential cannot enter.