v0.2.0
·
53 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Added
- Invocation Audit section in the FOSS UI, with audit event instrumentation
showing AI evaluation reasons, failed states, and clear handling of
no-match and deleted-rule cases. - Grounding eval suite for the LLM-as-judge, runnable against any
OpenAI-compatible endpoint. - Session context for the judge, reconstructed from Atryum-tracked tool
calls, with trust fencing, a byte cap, and expiry. - Pagination for the Invocations list UI.
- Auto-sync of agent charters from ValidMind, with stale-record
reconciliation on every sync. insert_beforesupport: rules created from "Always approve/deny" insert
at the top of the rule list and immediately apply their disposition to the
triggering invocation.rule_evaluatedaudit events for human-fallback dispositions, keyed by
rule ID.- Release builds run from a pristine clone of the release tag, with the
tag's commit stamped into the binaries as VCS provenance, and GitHub
release notes are drawn from this changelog. atryum versioncommand (also--version). Release builds report the
release tag and VCS revision; the same version is announced in MCP
handshake metadata (serverInfo/clientInfo) instead of a hardcoded
0.1.0.
Changed
- Rule creation from "Always approve/deny" now opens a pre-filled modal
instead of a bare form. - Shared agent hooks moved to the session model.
- Charter sync uses a JOIN instead of a subquery when listing ValidMind
CUIDs with bindings. - Token harness refreshed.
Fixed
- SSE updates no longer fail to refresh the invocation list after
pagination. - Rule-creation success callback branches on the saved rule's action rather
than the original menu item. - Disposition check matches what Atryum actually emits (
human, not
human_approval); human disposition copy corrected for direct
human-approval rules. - MCP server endpoints reject spaces.
ADD COLUMNstore migrations are idempotent.- Charter sync guards
DeleteSyncedStaleForOrgagainst an empty org CUID.
Security
- External session routes are gated behind authentication, and
RecordExecutionenforces session ownership. - Empty agent bindings are rejected on session mint and use.
- Judge session context is trust-fenced, byte-capped, and expiring;
tool-use caches are bounded.
What's Changed
- Don't allow spaces in mcp server endpoints by @mdeyell-valid-mind in #123
- [SC-16888] Reconcile stale agents on sync to prune archived/deleted VM records by @even-steven in #124
- Add pagination to Invocations list UI by @even-steven in #129
- Add Invocation Audit section to FOSS UI + audit event instrumentation by @even-steven in #127
- Token harness refresh by @mdeyell-valid-mind in #125
- Track tool history in sessions and reconstruct judge context server-side by @hunner in #126
- Refactor rule creation UX: pre-filled modal for always approve/deny by @even-steven in #132
- Add grounding eval suite for the LLM-as-judge by @hunner in #128
- Curated release notes and worktree-isolated release builds by @hunner in #134
- Build releases from a local clone of the tag, not a worktree by @hunner in #135
- Central version injected at release time, exposed via
atryum versionby @hunner in #136
Full Changelog: v0.1.0...v0.2.0