Releases: tszaks/pallium
Release list
v0.10.0 — Source-bound project knowledge
Pallium now gives agents compact project context with visible freshness, source evidence, and audit limits.
What changed
- Workspace-specific indexes and source-bound freshness prevent old prose from appearing current after edits.
- Exact module and receiver citations, collision-safe module IDs, improved TypeScript scanning, and explicit parser limitations.
- Compact CLI/MCP search and task context, source sections, tracked documentation/configuration, and explicitly linked decisions.
- A local knowledge browser with source evidence, audit outcomes, light/dark themes, and maintenance controls.
- Opt-in background upkeep with durable recovery, a global 40-attempt rolling daily cap, two active model slots, and deadlines.
Upgrade
npm install -g pallium@0.10.0
pallium index
pallium knowledge build --no-modelLegacy documents remain readable with rebuild labels. Compact response envelopes are version 2; use --full when full document payloads are needed. Use returned module IDs instead of constructing old slugs. Index linked worktrees separately.
Enable maintenance only for repositories whose source you intend the configured provider to read. Large initial builds remain subject to the same daily cap.
Evidence and limitations
All 30 controlled Go/TypeScript/Swift retrieval questions found the expected module in the top three. Two paired agent tasks used about 96% less supplied context with correct answers in both variants; no latency improvement or broad token-cost savings are claimed. Generated claims remain fallible, and heuristic parsers are incomplete.
See docs/releases/v0.10.0.md for migration and rollback details, and eval/knowledge/README.md for evaluation methodology.
PR: #85
v0.9.23 — Update itself
v0.9.23 — Update itself
pallium update brings the CLI current from wherever it is installed. No more
remembering whether a machine got pallium through npm, a release tarball, or
go install — the command detects the install shape and does the right thing.
What's new
- Self-update.
pallium update [--json]checks the latest GitHub release
against the running build and upgrades it. npm-managed installs (the binary
under~/.pallium/npm/) go throughnpm install -g pallium@latestso the
package metadata stays truthful; a bare binary gets the verified release
asset swapped in place — samechecksums.txtverification the installer
uses, staged next to the executable and renamed atomically. - Honest fallbacks. No npm on PATH under an npm layout falls back to the
binary swap; platforms without prebuilt assets say so and point atgo install; a checksum mismatch leaves the existing binary untouched. - Devin, first-class. This release also carries the Devin provider and
session support shipped in v0.9.22 for anyone updating from earlier.
Install
npm install -g pallium
pallium versionThen keep it current with:
pallium updatev0.9.22 — Devin, first-class
v0.9.22 — Devin, first-class
Pallium now treats the Devin CLI like Codex and Claude Code: workflows can
run Devin-backed workers, teams can give Devin teammates persistent native
sessions, and session awareness sees Devin CLI sessions alongside the others.
Run pallium from inside a Devin session and it adopts Devin automatically —
no configuration.
What's new
- Devin as a workflow provider.
agent(..., { provider: "devin" })runs
thedevinCLI headless, capturing the final answer, session id, and token
counts from the ATIF export rather than stdout. Read-only agents run
--permission-mode auto(fail-closed: write, exec, and networked tool calls
are all rejected); edit/test/check agents rundangerous. Steering
detection recognizes Devin viaCHISEL_SESSION_DB, and
PALLIUM_WORKFLOW_PROVIDER_DEVIN_COMMANDstill overrides with a wrapper. - Devin teammates with real session continuity. Team members on Devin
resume their own native session across turns via the exported session id —
the same contract codex and claude teammates already had. - Devin in
pallium sessions.sessions live,watch, andfindread
Devin's session database and classify lifecycle from message history —
running, waiting, blocked, finished — alongside Codex and Claude. - Devin session memory.
sessions index/sync --provider devin
(--devin-dbfor a non-default database) normalize Devin's SQLite history
into the shared schema, sosearch,recall,show, andreadanswer
from Devin transcripts withdevin:citations.
Known limitations
- Devin edit agents may reach the network regardless of
network: true.
--permission-mode dangerousauto-approves networked tools; conversely a
networked read-only request can't be granted (autoblocks egress) and
logs a warning. Use a configured wrapper for tighter egress control. - Devin cost is not tracked in USD. Devin reports ACU/token metrics, so
it joins codex on the untracked-cost list —team status/loop status
say so explicitly instead of showing an indistinguishable $0.0000.
Install
npm install -g pallium
pallium versionv0.9.21 — Know the codebase, not just its history
v0.9.21 — Know the codebase, not just its history
Pallium's repo intelligence was built entirely from git history. It could tell
you which files move together and how risky one is to touch, and nothing at all
about what any of them contained. There was no symbol anywhere in the index and
no command that searched code.
This release adds the other half: a content index of symbols and import edges,
and a knowledge base built on top of it that refuses to store a claim it cannot
check.
What's new
-
pallium indexindexes content, not just commits. Per file it records a
content hash, its symbols with kind, line range, signature and doc comment,
its resolved import edges, and the identifiers it references. Go parses
throughgo/parser; TypeScript, JavaScript, Python, Swift, Rust, Ruby, Java,
Kotlin, C#, PHP and C/C++ use line-anchored scanners, because Pallium ships
as a single cgo-free binary and a native grammar would break both
cross-compilation and the npm install. The content half is keyed by hash, so
reindexing only reparses what changed: 2,458 symbols across 186 files in
0.43s on Pallium itself, and a second run reparses nothing. -
pallium symbols <path>lists what a file declares, with kinds, line
numbers, signatures and doc comments, plus the files it imports and the files
that import it. -
pallium callers <name>separates where a name is declared from where it
is merely referenced, which is what sizing a rename actually needs. -
pallium search <query>runs FTS5 over symbol names, signatures and doc
comments, name matches ranked first. -
pallium knowledge map|build|audit|list|get|searchbuilds a readable
description of what each part of a repo is for. Modules are clustered from
the content index; their file lists, symbol surfaces ranked by how many files
reference each name, dependency edges in both directions, external packages
and recent history are all derived, so they are correct by construction. An
incidentsdoc is mined from commit subjects announcing reverts, rollbacks,
hotfixes and outages, so every entry is a real SHA with a real file list.
--no-modelbuilds the whole base with no model calls at all. -
A model fills a schema; it never writes the page. Synthesis returns a
fixed JSON shape of cited claims and the renderer builds the markdown, so
there is no path for an unchecked citation to reach a doc body. Every cited
path and symbol is checked against the index before storage; a claim citing
something that does not exist is deleted, recorded in the doc's dropped
claims, and the doc is marked unverified. -
pallium knowledge auditchecks whether claims are true, not just
citable. Verification proves a citation resolves. It does not prove the
claim about that symbol is correct: "Open deletes the database", citing a
realOpen, passes. The audit hands a skeptic each stored claim together
with the real source of every symbol it cites and removes what the source
does not support.Measured on Pallium's own knowledge base: 325 claims, 134 supported, 168
unclear, 23 removed. Four removals were spot-checked against the source by
hand and all four were correct — the audit caught a claim that the indexer
wraps branch detection inside its transaction (it does not; two git reads
happen before it opens), a claim that a recency clamp guards against
same-day commits (the expression already adds one, so the clamp only fires
on future timestamps), a claim that a reindex wipes every repo table (the
delete list is explicit), and an invented eight-value symbol-kind
vocabulary that nothing enforces.The
unclearrate is high and that is the intended behavior, not a
shortfall: over half of all claims concern behavior spanning more code than
one declaration's excerpt shows, andunclearis a first-class verdict
because forcing a binary answer on insufficient evidence either deletes good
knowledge or keeps bad. The audit only ever removes what it can justify. -
Seven knowledge tools on the MCP surface.
pallium workflow mcp
previously exposed workflow tools only, so a connected agent could start a
run but could not ask one question about the repo. It now serves
pallium_knowledge_search,_getand_map, pluspallium_explain,
_symbols,_callersand_search_code. Knowledge search is BM25-ranked,
not substring matching. -
pallium explainsays what a file is before saying how risky it is. Its
summary used to be one of three fixed strings chosen by risk level. It now
leads with what the file declares and which module it belongs to. -
Synthesis fans out. One provider call per module measured at ~55s, so
knowledge buildruns them concurrently (--concurrency, default 4) while
verification and storage stay strictly sequential, since a repo's sqlite file
has exactly one writer by design. Pallium's own 18 modules build in 2m55s.
Fixed
explain,riskandreviewno longer read your dependency tree to
answer one question. The file listing walked the working tree and skipped
only.git,.palliumand.codex-memory, so a repo withnode_modulesor
vendorpaid for all of it on every call. Measured on a three-file repo with
one real import: 1.9s clean, 12.2s with 20,000 gitignored files beside it,
same single result. It now asksgit ls-files, which inherits.gitignore,
and caps scanned files at 512KB so a minified bundle is never regexed.- TypeScript ESM import specifiers resolve. An import written
from "../server/auth.js"whose source on disk isauth.tsis TypeScript's
NodeNext convention, not an oddity. It resolved to nothing, which meant an
entire directory of a real 858-file Next.js app reported zero in-repo
dependencies. - A parser improvement now reaches existing indexes. A content hash cannot
notice that Pallium got better at reading a file, so after an upgrade every
hash matched, nothing reparsed, and a stale index persisted indefinitely.
code_filesstores a versioned parser tag and a mismatch forces a reparse. - Import resolution has one implementation.
internal/analysiscarried its
own copy of the Go, tsconfig-alias and Python resolution rules, which had to
stay in sync with the indexer by hand. Both paths now call
codeindex.Parse, and a test pins the indexed and fallback implementations
ofStructuralLinksto byte-identical output so the fallback cannot rot. - An audit cannot report unauditable docs as clean. Docs written before
claims were stored alongside the rendered body have nothing to re-check;
they are now counted separately and named, instead of being folded into
"skipped as structural-only". - Evidence is scoped to the module being documented. Symbol names repeat
across packages — Pallium declaresStorein four,Runin six — so
resolving a cited name repo-wide and taking the first match handed the
auditor a stranger's source. It then refuted 44 true claims, correctly, on
code that had nothing to do with them. Resolution now prefers the claim's
own cited paths, then the module's files, then reports the symbol as not
found, because silently omitting evidence makes absence of proof read as
disproof. - Neither build nor audit will touch a module the index has not seen. Both
hand stored line numbers, signatures and doc comments to a model as fact, so
a file that grew since indexing points them at whatever now occupies those
lines. One file had drifted 28 lines and an excerpt labelled*Store.Repo
was actuallyWithTx's body. A module whose files no longer hash to the
index is skipped and counted (--allow-staleoverrides on build), and every
excerpt must show its declaration's own name within three lines of where the
index claims it starts, so any future drift degrades to missing evidence
rather than wrong evidence.
Upgrading
Existing indexes keep working: a repo without a content index falls back to the
previous behavior, and pallium index fills it in. Run pallium index once per
repo after upgrading, then pallium knowledge build --no-model for a base that
costs nothing.
Install
npm install -g pallium
pallium versionv0.9.20 — Route model and effort deliberately
v0.9.20 — Route model and effort deliberately
Pallium can now select provider, model, and reasoning effort through one
inspectable policy. Explicit choices still win, Auto routing remains opt-in,
and every provider attempt records the configuration and available usage
evidence needed to evaluate routing safely.
What's new
- Route complete execution configurations.
pallium route modelsmanages
provider, model, and reasoning-effort choices together instead of treating
the model name as the whole decision. - Apply routing across workflows and teams. Agents, checks, gates, and team
members share the same policy while preserving explicit pins and allowed
provider boundaries. - Inspect invocation evidence. Workflow reports record requested execution
settings, duration, status, token usage, and known cost across retries. - Evaluate policies locally. A versioned fixture set and evaluation harness
support bounded trials, independent grading, comparison reports, and shadow
policy proposals without automatically promoting an unproven route.
Fixed
- Evaluation results cannot mix different execution identities. Candidate,
routing-config, Pallium binary, and worker CLI identities are pinned before
results can be compared or proposed. - Team Auto routing can choose the provider. An omitted provider remains
unpinned until the routing policy makes its selection. - Objective checks include untracked files. Evaluation trials now reject
newly created test files as well as modified tracked tests. - Invocation history distinguishes configuration failures. Unsupported or
unavailable configurations are recorded as not dispatched instead of being
reported as sent to a provider. - Gate approvals follow the effective route. Cached approvals are
invalidated when provider availability or another routing input changes the
selected provider, model, or effort. - Claude failure accounting keeps reported usage. Error envelopes retain
token and cost evidence so failed paid attempts remain inside workflow and
team budget accounting. - Codex event streams stay memory-bounded. Usage is accumulated while the
stream is read, and only a small diagnostic tail is retained for failures. - Real routing trials cannot inherit drifting Codex settings. Non-simulation
evaluation runs require the isolated Codex configuration path. - Team policy checks use the live repository root. Edit worktrees can no
longer miss a gitignored routing policy after an operator removes a provider. - Team routing covers the complete member lifecycle. Task classes reach the
policy, Codex executable checks are deferred to the configured team runner,
plan-required members select an edit-eligible route, and pre-dispatch team
failures are recorded honestly. - Routing evidence stays attached to its real source. Policy suggestions
require the same recorded config, malformed or empty invocation snapshots
cannot be graded, redirected test databases remain isolated, and
workflow-created team gates retain invocation history. - A dispatch begins only when a provider process starts. Validation and
process-start failures from workflows and teams are retained as
not_dispatchedinstead of disappearing or posing as executed calls. - Provider capabilities match the actual adapter. Configured wrappers own
their reasoning-effort vocabulary, while the networkless built-in Claude
adapter is excluded from routes that require network access.
Install
npm install -g pallium
pallium versionv0.9.19 — Use the agent, not the menu
v0.9.19 — Use the agent, not the menu
Pallium now helps an agent choose and use the right capability from a plain
statement of intent. It also understands session completion and recency, so an
agent can reason about current and recent work without treating transcript
keywords or process names as proof.
What's new
- Route and act from intent.
pallium route <task> --executeselects a named
capability, explains its evidence and alternatives, and invokes the command
with structured arguments when it fits the caller's existing authority. - Discover the decision contract.
pallium route capabilities --json
exposes when each capability fits, when to avoid it, its required authority,
and the evidence that demonstrates success. - Ask natural questions about sessions.
pallium sessions find <query>
understands recently finished, unfinished, inactive, and most-recently
updated sessions. It returns the interpretation and filters it applied. - Distinguish runtime state from completion. Session results separately
report whether a process is active and whether transcript evidence shows the
task finished, did not finish, or remains unknown.
Fixed
- Live discovery no longer counts helper processes as agent sessions. Exact
process identity prevents Codex host helpers from appearing as duplicate
running work. - Live-state claims carry evidence and coverage. State reasons, sources,
confidence, timestamps, provider coverage, and explicit exclusions prevent a
best-effort local view from posing as an exhaustive computer inventory. - Running-session requests exclude completed open tasks. The router uses
sessions live --running-only, keeping finished desktop tabs out of the
answer while retaining their lifecycle evidence when explicitly requested. - Workflow concurrency tests no longer depend on fixed sleeps. Marker-based
synchronization removes a timing-sensitive failure from the full test suite.
Install
npm install -g pallium
pallium versionv0.9.18 — Pick up where you left off
v0.9.18 — Pick up where you left off
Pallium can now turn prior Codex and Claude sessions into useful continuity:
what the work was, where it stopped, and what should happen next. This release
also restores Pallium's optional MCP tools in Codex by speaking the standard
stdio transport correctly.
What's new
- Recall work across sessions.
pallium sessions recall <question>combines
lexical and semantic retrieval, then returns a bounded continuity capsule
with the goal, decisions, files, blockers, and next action from the best
matching session. - Keep the session index healthy. Session sync, maintenance, and retrieval
now cover Codex and Claude history more reliably, including archived sessions,
legacy records, duplicate messages, stale embeddings, and permanently failed
embedding jobs. - Configure embeddings once. Embedding settings persist locally, with API
credentials stored in the macOS Keychain instead of the Pallium database. - Find a Codex goal file directly.
pallium sessions goal <session-id>
resolves the goal attachment for a session. Use--path-onlyfor scripts or
--jsonfor structured output.
Fixed
- Pallium MCP works in Codex again. The workflow MCP server now uses the
newline-delimited JSON transport required for stdio MCP servers, eliminating
the startup timeout caused by the oldContent-Lengthframing. - Incomplete workflow schemas fail early and clearly. Startup now verifies
that existing workflow, team, and loop tables contain every expected column,
so a missed migration is reported immediately instead of surfacing later as
an unrelated query failure.
Install
npm install -g pallium
pallium versionv0.9.17 — Teams, made adoptable
v0.9.17 — Teams, made adoptable
This release closes the teams trilogy: possible, composable, and now
adoptable. Ready-made team shapes, a way for any running agent session to
join a team directly, and a more forgiving decision format.
What's new
- Team templates.
pallium team start <goal> --template parallel-review
oradversarial-debatespawns a known-good team shape in one command —
distinct-lens reviewers on the same artifact, or two members arguing
opposite sides of a question.team template listto browse. - Join a team from any session.
pallium team join <team-id> --as <name>
lets an already-running agent session — another editor tab, a different
CLI, a person at a terminal — join a team and coordinate through its
shared mailbox, with no separate setup. - A more forgiving decision format. Teammates no longer need to include
every optional field for their decisions to count. A genuinely broken
decision is never silently ignored either — you'll hear about it. - The setup guide now covers teams and loops. The trigger Pallium
installs into your project only ever mentioned workflows before this
release. It now mentions all of Pallium's capabilities, so a fresh agent
session can actually discover team and loop support.
Fixed
- Task completion is now reliable. A teammate that finished real work
could previously leave the task board showing it as still pending. Fixed.
Install
npm install -g pallium
pallium versionv0.9.16 — Teams become composable
v0.9.16 — Teams become composable
Agent Teams can now be driven from workflow scripts, need real plan review
before editing, and support quality gates and per-teammate supervision.
What's new
- Teams from workflow scripts. A workflow (or a loop tick) can now
create and drive a whole team programmatically — spawn teammates, send
messages, wait for convergence, and read back the result, all from code. - Plan approval. A teammate can be required to submit a plan and wait for
it to be approved before it's allowed to make any edits. - Quality gates. Configure an autonomous verifier that checks a team's
work at key points — when a task is created, when one is completed, or
when a teammate goes idle — and can send it back for another pass. - Supervise one teammate at a time.
team member stop|restart|steerlets
you pause, resume, or redirect a single teammate without touching the rest
of the team. Changes take effect at that teammate's next turn, so nothing
is ever interrupted mid-thought. - Honest cost reporting. Team spend reporting now says plainly which
providers don't report real usage data, instead of showing a misleading
$0.00.
Install
npm install -g pallium
pallium versionv0.9.15 — Operational honesty
v0.9.15 — Operational honesty
Pallium now tells you plainly when something is actually done, and cleans up
after itself when a process dies unexpectedly.
What's new
- Stale runs clean themselves up. If the process running a workflow gets
killed, its run and workers used to look "running" forever. Every run now
tracks its own liveness and automatically flips to an honest "interrupted"
status once its owning process is gone — checked every time you list,
inspect, or check on your runs.workflow gc --staleruns the same cleanup
as an explicit command. - An unmissable verdict.
workflow statusandreportnow lead with a
blunt "FINISHED" or "NOT FINISHED" line, so it's never ambiguous whether a
run actually completed. - The setup prompt installs itself.
pallium startnow offers to add
Pallium's adoption block to yourAGENTS.md/CLAUDE.mdthe first time it
notices one is missing, instead of leaving that step for you to remember.
Install
npm install -g pallium
pallium version