What's Changed
- docs: credit external contributors by handle in CHANGELOG by @tishachawla-jg in #104
- docs(security): state the trust model in SECURITY.md by @tishachawla-jg in #105
- docs(security): add public threat model by @tishachawla-jg in #106
- docs: note Chronicle's REALM @ EMNLP 2026 acceptance by @tishachawla-jg in #108
- docs: note Secure Open Source Fund participation by @tishachawla-jg in #112
- Disable trajectory_hint (remote-only prep) by @susheem-k in #119
- LedgerBackend protocol + HttpLedgerBackend (remote-only, Phase 2.1) by @susheem-k in #120
- Ledger.close_run() + skip zero-cost spend writes (remote-only prep) by @susheem-k in #121
- docs: remove Secure Open Source Fund line from the hero by @tishachawla-jg in #126
- fix: bring e2e tests into default CI, fix 3 stale against attribution hardening by @susheem-k in #130
- refactor: rename RunState to LocalRunState; add PolicyInstance.data_scope by @susheem-k in #131
- docs: add raise-issue skill for writing newcomer-readable issues by @susheem-k in #134
- chore: release 0.3.0 by @susheem-k in #136
Full Changelog: v0.2.1...v0.3.0