Skip to content

v0.3.3 — AI Open Source Intelligence

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Aug 18:19

Changelog

All notable pre-release changes are recorded here. Dates refer to repository changes, not public availability.

[Unreleased]

[0.3.3] - 2026-08-29

Changed

  • Tightened the unified Skill's evidence workflow so one valid selector result
    is preserved, candidate-specific selector retries cannot be used to fill
    evidence gaps, and every shortlisted project receives exactly one facts and
    one License evidence check before synthesis.
  • Preserved alternative preferences such as low-code or no-code as separate
    preferred constraints instead of collapsing the user's acceptable options.
  • Required final reports to cite the dedicated License check record and its
    observation time even when direct License evidence remains unknown.

Fixed

  • Rejected unsupported or ambiguous required constraints at the local MCP
    boundary with INVALID_INPUT, while retaining the canonical
    id/value/polarity contract and preventing semantic duplicates from
    reaching the Radar selector.
  • Clarified that summaries, directory projections and mutable README references
    remain partial unless the returned project evidence directly verifies the
    claim, and that missing hard-condition evidence must remain an explicit
    near-match blocker.

[0.3.2] - 2026-08-28

Changed

  • Published the complete typed-constraint shape through the actual MCP runtime,
    preserved preferred constraints, and normalized common deployment, Web UI and
    low-code aliases.
  • Added deterministic directory fallback discovery, claim-level README evidence
    for self-hosting/Docker/Web UI/low-code conditions, per-candidate constraint
    evaluations, and post-hydration hard-requirement enforcement.
  • Replaced the comparison placeholder matrix with criterion-specific evidence
    states and preserved comparison context and per-project freshness.
  • Added discovery-only observed License labels and support for dedicated public
    license_evidence rows without weakening the direct-evidence requirement.
  • Strengthened the public probe, offline fixture replay and bilingual Plugin
    evaluation corpus so formal candidates must retain typed constraints and
    satisfy every hard requirement while near matches expose blockers.

Fixed

  • Fixed unresolved constraint references in the search and stack-planning
    manifest schemas and added runtime/manifest schema regression checks.
  • Prevented same-snapshot listing/detail disagreements from entering verified
    facts and separated response observation time from source freshness.
  • Prevented selector candidates with unknown hard requirements from appearing
    as formal matches; they now become explicit near matches with blockers.
  • Prevented negated README statements such as unsupported Docker or missing Web
    UI from being promoted into positive condition evidence.
  • Restricted explicit repository evidence URLs to the candidate repository and
    used safe upstream commit/ref values when constructing immutable source links.

[0.3.1] - 2026-08-28

Changed

  • Strengthened the unified Skill as the single product entry point with
    explicit intent routing, project-identity resolution, evidence/freshness
    rules, bounded retry behavior, privacy boundaries and non-activation scope.
  • Added skills/ai-open-source-intelligence/agents/openai.yaml so the Skill
    declares its canonical read-only Hosted MCP dependency and implicit
    invocation policy independently of Plugin-level connection packaging.
  • Expanded bilingual Plugin evaluations to cover every internal route,
    clarification behavior, tool sequences, Skills-only fallback and explicit
    non-activation cases.
  • Replaced the repository's Skills-only Plugin package with a complete package
    that bundles the unified Skill and the production Hosted MCP configuration.
  • Kept the remote MCP runtime independently deployed and preserved v0.3.0 as
    an immutable historical artifact; the complete package requires a new patch
    release.
  • Aligned public listing copy and starter prompts with current directory limits
    and added the required square Plugin logo/composer icon.

Fixed

  • Made Plugin validation, release readiness and deterministic bundle checks
    fail closed when the Skill-level MCP dependency is missing or drifted.
  • Made Codex acceptance and its evidence validator fail closed on a dirty
    or changed worktree so uncommitted behavior cannot be attributed to the
    recorded SHA before or during the acceptance run.
  • Applied the same clean-candidate rule to Hosted remote smoke and aggregate
    evidence readiness, with new Codex/Hosted evidence schema versions.
  • Expanded CI type checking to the Skill packaging and candidate-evidence
    modules used by the publication gate.
  • Added missing evidence-readiness and Codex configuration files to the Plugin
    archive and validate that packaged Markdown links resolve inside the ZIP.
  • Aligned the complete Plugin with the canonical Codex ingestion contract by
    using the standard skills/ root and the .mcp.json mcpServers shape,
    removing an unsupported interface field, and separating marketplace
    installation policy from the anonymous Hosted MCP authentication mode.
  • Aligned active onboarding, architecture, security, deployment and Alpha docs
    with the released one-Skill, nine-tool v0.3.0 product and its production
    Hosted deployment.
  • Added current ChatGPT Developer mode, Codex Hosted MCP and PyPI installation
    paths without claiming public plugin-directory approval.
  • Replaced the plugin Terms URL that returned 404 and added regression checks
    for pre-v0.3.0 tool-count copy.
  • Corrected the osi-m0 list-tools help text and Codex allowlist example from
    six tools to nine.

[0.3.0] - 2026-08-10

Changed

  • Rebuilt the public contract around one version source, nine tools and osi.tool-result.v2 / osi.error.v2 envelopes.
  • Replaced untyped constraint maps with typed {id, value, polarity} arrays and removed the inactive source_mode parameter.
  • Documented ephemeral selector control-plane effects while retaining the non-destructive, business-data read-only boundary.

[0.2.0] - 2026-08-09

Changed

  • Replaced three overlapping user-facing Skills with one unified ai-open-source-intelligence Skill that internally routes browsing, research, fact checking, comparison, alternatives and stack planning.
  • Moved the active Skill root to product-skills/ and removed the old split Skill paths from the product and distribution bundle.
  • Made the Hosted product strictly data/evidence-only: exactly nine read-only Radar tools, no runtime OAuth mode, no Premium tool, no checkout/credit path and no AI Workstation server-side model execution.
  • Locked requirement-based Radar selection to the deterministic public selector contract with use_model=false and added regression coverage for that invariant.
  • Added canonical AI Workstation, AI Open Source Radar and open-source-project links to every MCP tool result under data.official_resources; the unified Skill may surface those links once as publisher resources without mixing them into verified facts.
  • Tightened anonymous Hosted abuse controls with short-window plus sustained per-IP request limits and a lower concurrent-connection cap.
  • Updated Plugin metadata, package metadata, CI, manifests, readiness logic, container configuration and documentation to match the one-Skill/data-only product.

Security

  • OSI_HOSTED_ACCESS_MODE=oauth now fails closed instead of re-enabling a hidden OAuth/Premium/server-model route.
  • Public Hosted Compose no longer carries OAuth, backend-service-token or Premium environment variables.
  • Dedicated MCP Nginx configuration no longer forwards Authorization or exposes OAuth metadata routes in the data-only release.

[0.1.0] - 2026-08-09

Added

  • Initial Apache-2.0 public repository and evidence-backed open-source AI research workflows.
  • Nine standard read-only Radar MCP tools covering project discovery, facts, license evidence, comparison, alternatives, stack planning, Radar overview, project browsing and Radar Skills browsing.
  • Hardened public Radar HTTP provider, bilingual live-contract validation, deterministic Skills packaging, Codex acceptance and evidence-first release readiness.
  • Candidate-bound Hosted MCP deployment identity, Docker packaging, TLS/Nginx gateway templates, remote MCP validation and Hosted Private Alpha readiness.
  • Initial public Hosted deployment architecture and production abuse controls.

Changed

  • Public project facts distinguish verified public metadata/direct evidence from editorial projections and unknowns.
  • Verified license output requires direct public License evidence rather than relying on a label alone.
  • Hard requirements remain explicit and are never silently relaxed to manufacture a match.