v0.3.3 — AI Open Source Intelligence
Pre-release
Pre-release
Changelog
All notable pre-release changes are recorded here. Dates refer to repository changes, not public availability.
[Unreleased]
[0.3.3] - 2026-08-29
Changed
- Tightened the unified Skill's evidence workflow so one valid selector result
is preserved, candidate-specific selector retries cannot be used to fill
evidence gaps, and every shortlisted project receives exactly one facts and
one License evidence check before synthesis. - Preserved alternative preferences such as low-code or no-code as separate
preferred constraints instead of collapsing the user's acceptable options. - Required final reports to cite the dedicated License check record and its
observation time even when direct License evidence remainsunknown.
Fixed
- Rejected unsupported or ambiguous required constraints at the local MCP
boundary withINVALID_INPUT, while retaining the canonical
id/value/polaritycontract and preventing semantic duplicates from
reaching the Radar selector. - Clarified that summaries, directory projections and mutable README references
remainpartialunless the returned project evidence directly verifies the
claim, and that missing hard-condition evidence must remain an explicit
near-match blocker.
[0.3.2] - 2026-08-28
Changed
- Published the complete typed-constraint shape through the actual MCP runtime,
preserved preferred constraints, and normalized common deployment, Web UI and
low-code aliases. - Added deterministic directory fallback discovery, claim-level README evidence
for self-hosting/Docker/Web UI/low-code conditions, per-candidate constraint
evaluations, and post-hydration hard-requirement enforcement. - Replaced the comparison placeholder matrix with criterion-specific evidence
states and preserved comparison context and per-project freshness. - Added discovery-only observed License labels and support for dedicated public
license_evidencerows without weakening the direct-evidence requirement. - Strengthened the public probe, offline fixture replay and bilingual Plugin
evaluation corpus so formal candidates must retain typed constraints and
satisfy every hard requirement while near matches expose blockers.
Fixed
- Fixed unresolved
constraintreferences in the search and stack-planning
manifest schemas and added runtime/manifest schema regression checks. - Prevented same-snapshot listing/detail disagreements from entering verified
facts and separated response observation time from source freshness. - Prevented selector candidates with unknown hard requirements from appearing
as formal matches; they now become explicit near matches with blockers. - Prevented negated README statements such as unsupported Docker or missing Web
UI from being promoted into positive condition evidence. - Restricted explicit repository evidence URLs to the candidate repository and
used safe upstream commit/ref values when constructing immutable source links.
[0.3.1] - 2026-08-28
Changed
- Strengthened the unified Skill as the single product entry point with
explicit intent routing, project-identity resolution, evidence/freshness
rules, bounded retry behavior, privacy boundaries and non-activation scope. - Added
skills/ai-open-source-intelligence/agents/openai.yamlso the Skill
declares its canonical read-only Hosted MCP dependency and implicit
invocation policy independently of Plugin-level connection packaging. - Expanded bilingual Plugin evaluations to cover every internal route,
clarification behavior, tool sequences, Skills-only fallback and explicit
non-activation cases. - Replaced the repository's Skills-only Plugin package with a complete package
that bundles the unified Skill and the production Hosted MCP configuration. - Kept the remote MCP runtime independently deployed and preserved
v0.3.0as
an immutable historical artifact; the complete package requires a new patch
release. - Aligned public listing copy and starter prompts with current directory limits
and added the required square Plugin logo/composer icon.
Fixed
- Made Plugin validation, release readiness and deterministic bundle checks
fail closed when the Skill-level MCP dependency is missing or drifted. - Made Codex acceptance and its evidence validator fail closed on a dirty
or changed worktree so uncommitted behavior cannot be attributed to the
recorded SHA before or during the acceptance run. - Applied the same clean-candidate rule to Hosted remote smoke and aggregate
evidence readiness, with new Codex/Hosted evidence schema versions. - Expanded CI type checking to the Skill packaging and candidate-evidence
modules used by the publication gate. - Added missing evidence-readiness and Codex configuration files to the Plugin
archive and validate that packaged Markdown links resolve inside the ZIP. - Aligned the complete Plugin with the canonical Codex ingestion contract by
using the standardskills/root and the.mcp.jsonmcpServersshape,
removing an unsupported interface field, and separating marketplace
installation policy from the anonymous Hosted MCP authentication mode. - Aligned active onboarding, architecture, security, deployment and Alpha docs
with the released one-Skill, nine-toolv0.3.0product and its production
Hosted deployment. - Added current ChatGPT Developer mode, Codex Hosted MCP and PyPI installation
paths without claiming public plugin-directory approval. - Replaced the plugin Terms URL that returned
404and added regression checks
for pre-v0.3.0tool-count copy. - Corrected the
osi-m0 list-toolshelp text and Codex allowlist example from
six tools to nine.
[0.3.0] - 2026-08-10
Changed
- Rebuilt the public contract around one version source, nine tools and
osi.tool-result.v2/osi.error.v2envelopes. - Replaced untyped constraint maps with typed
{id, value, polarity}arrays and removed the inactivesource_modeparameter. - Documented ephemeral selector control-plane effects while retaining the non-destructive, business-data read-only boundary.
[0.2.0] - 2026-08-09
Changed
- Replaced three overlapping user-facing Skills with one unified
ai-open-source-intelligenceSkill that internally routes browsing, research, fact checking, comparison, alternatives and stack planning. - Moved the active Skill root to
product-skills/and removed the old split Skill paths from the product and distribution bundle. - Made the Hosted product strictly data/evidence-only: exactly nine read-only Radar tools, no runtime OAuth mode, no Premium tool, no checkout/credit path and no AI Workstation server-side model execution.
- Locked requirement-based Radar selection to the deterministic public selector contract with
use_model=falseand added regression coverage for that invariant. - Added canonical AI Workstation, AI Open Source Radar and open-source-project links to every MCP tool result under
data.official_resources; the unified Skill may surface those links once as publisher resources without mixing them into verified facts. - Tightened anonymous Hosted abuse controls with short-window plus sustained per-IP request limits and a lower concurrent-connection cap.
- Updated Plugin metadata, package metadata, CI, manifests, readiness logic, container configuration and documentation to match the one-Skill/data-only product.
Security
OSI_HOSTED_ACCESS_MODE=oauthnow fails closed instead of re-enabling a hidden OAuth/Premium/server-model route.- Public Hosted Compose no longer carries OAuth, backend-service-token or Premium environment variables.
- Dedicated MCP Nginx configuration no longer forwards Authorization or exposes OAuth metadata routes in the data-only release.
[0.1.0] - 2026-08-09
Added
- Initial Apache-2.0 public repository and evidence-backed open-source AI research workflows.
- Nine standard read-only Radar MCP tools covering project discovery, facts, license evidence, comparison, alternatives, stack planning, Radar overview, project browsing and Radar Skills browsing.
- Hardened public Radar HTTP provider, bilingual live-contract validation, deterministic Skills packaging, Codex acceptance and evidence-first release readiness.
- Candidate-bound Hosted MCP deployment identity, Docker packaging, TLS/Nginx gateway templates, remote MCP validation and Hosted Private Alpha readiness.
- Initial public Hosted deployment architecture and production abuse controls.
Changed
- Public project facts distinguish verified public metadata/direct evidence from editorial projections and unknowns.
- Verified license output requires direct public License evidence rather than relying on a label alone.
- Hard requirements remain explicit and are never silently relaxed to manufacture a match.