From 43c0290962f94b5ebfcab4e9615b0238e0d2c6b8 Mon Sep 17 00:00:00 2001 From: Brad Groux <3053586+BradGroux@users.noreply.github.com> Date: Wed, 2 Sep 2026 23:52:09 -0500 Subject: [PATCH] docs: record current 6.1.4 release state --- docs/DOC-FRESHNESS.md | 1 + docs/V6-COMPATIBILITY-AND-RELEASE-POLICY.md | 10 +++--- docs/V6-GA-CHECKLIST.md | 21 ++++++++--- docs/V6-RC-EVIDENCE-PACKET.md | 35 ++++++++++++++++--- docs/V6-RELEASE-NOTES.md | 20 +++++++---- docs/V6-UPGRADE-INSTALL-ADMIN-GUIDE.md | 22 ++++++------ .../V6-AGENT-RUNTIME-CONTROL-PLANE.md | 6 ++-- 7 files changed, 79 insertions(+), 36 deletions(-) diff --git a/docs/DOC-FRESHNESS.md b/docs/DOC-FRESHNESS.md index 96254728..8459b47a 100644 --- a/docs/DOC-FRESHNESS.md +++ b/docs/DOC-FRESHNESS.md @@ -67,6 +67,7 @@ update the authoritative registry record. | Date | Scope | Agent | | ---------- | ------------------------------------------------------------------------------------------ | ------- | +| 2026-09-02 | v6.1.4 release, install, compatibility, runtime, distribution, and evidence docs | Release | | 2026-08-30 | README; v6.1.3 access, automation, artifacts, provenance, UI, security, and release docs | Release | | 2026-08-24 | README; v6.1.2 audit, storage, provider, CI, security, release, distribution, and SOP docs | Release | | 2026-08-22 | v6.1.1 maintenance, dependency, release, upgrade, and evidence docs | Release | diff --git a/docs/V6-COMPATIBILITY-AND-RELEASE-POLICY.md b/docs/V6-COMPATIBILITY-AND-RELEASE-POLICY.md index e7d9ba4e..249a4fac 100644 --- a/docs/V6-COMPATIBILITY-AND-RELEASE-POLICY.md +++ b/docs/V6-COMPATIBILITY-AND-RELEASE-POLICY.md @@ -1,11 +1,11 @@ # Veritas Kanban v6 Compatibility And Release Policy -This policy defines supported v6.1.3 combinations, harness evidence, release +This policy defines supported v6.1.4 combinations, harness evidence, release channels, and rollback limits. The machine-readable harness record at `GET /api/config/harness-compatibility` is authoritative for exact capability digests, fixture revisions, and the current host's live state. -Documentation freshness: 2026-08-30 for Veritas Kanban 6.1.3. +Documentation freshness: 2026-09-02 for Veritas Kanban 6.1.4. ## Harness Support Tiers @@ -25,19 +25,19 @@ are incompatible with v6. | Component | Supported v6 combination | Detection/evidence | Fail-closed boundary | | -------------------------------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | -| Server, web, shared, CLI, MCP, desktop | All release packages are exactly 6.1.3. | Package manifests, `/api/health.version`, `vk --version`, MCP metadata, desktop bundle/update metadata. | Mixed release packages are unsupported for publication. | +| Server, web, shared, CLI, MCP, desktop | All release packages are exactly 6.1.4. | Package manifests, `/api/health.version`, `vk --version`, MCP metadata, desktop bundle/update metadata. | Mixed release packages are unsupported for publication. | | Public API | REST API remains `v1` at `/api/v1`, with `/api` compatibility aliases where documented. | `X-API-Version`, OpenAPI/reference docs, CLI/MCP smoke. | Unknown API versions or incompatible auth fail before mutation. | | Buzz Agent | Buzz v0.4.24 commit `710ed9fff57878a1d69f809b80a6ee0416c53fc4`; `buzz-agent 0.1.0`; ACP v1. | Exact initialize identity, capability digest, probe revision, composed Buzz fixtures. | Unknown build, `buzz-acp`, resume, HTTP/SSE MCP, or capability drift blocks. | | Buzz relay integration | Buzz v0.4.24; NIP-11, NIP-29, NIP-42; optional NIP-43 membership. | Pinned relay compatibility evidence, signed query/event fixtures, mapping state. | Host/TLS drift, unsafe URL, bad signature, identity mismatch, replay, or disabled mapping blocks. | | Grok Build | v0.2.111 build `94172f2aa4e5`; generic ACP v1. | Exact version/build and `x.ai` capability handshake. | Unknown version, approval bypass, leader/plugin/endpoint injection, or unsupported controls blocks. | | Codex CLI | Explicit `codex-cli` adapter with exact runtime probe. | `codex --version`, `codex login status`, runtime manifest. | Missing adapter evidence or requested unsupported controls blocks. | -| Codex SDK | `@openai/codex-sdk 0.144.3`. | SDK import plus Codex authentication and runtime manifest. | Missing SDK/authentication or unsupported controls blocks. | +| Codex SDK | `@openai/codex-sdk 0.149.0`. | SDK import plus Codex authentication and runtime manifest. | Missing SDK/authentication or unsupported controls blocks. | | Codex app-server | `codex-cli 0.145.0`, upstream commit `25af12f7e61572b0bc18ddb1008be543b91519b0`. | Generated v2 schemas, exact version, remote control disabled, deterministic and optional live smoke. | Schema drift, remote control, inherited plugins/apps/hooks/browser/computer tools, or unsandboxed shell method blocks. | | Claude Code | `2.1.218 (Claude Code)`. | Version, auth status, agent discovery, stream fixtures, optional live smoke. | Permission bypass, inherited config/plugins, unsupported lifecycle request, bad stream, or missing authoritative result blocks. | | GitHub Copilot CLI | v1.0.74 public-preview ACP; tag commit `2b809c84e87dbcc88f897cb4f3fb97c43b77af95`. | Version and ACP initialize handshake; authentication remains provider-managed. | Version drift, broad allow, remote/plugin/config injection, or unsupported controls blocks. | | Hermes Agent | v2026.7.7.2 one-shot process adapter. | `hermes --version` and allowlisted boot authentication. | Resume/follow-up remains unsupported. | | OpenClaw | v2026.6.11 gateway adapter. | Gateway health, runtime manifest, explicit operator tool policy. | Missing `sessions_spawn`/`sessions_send`, unknown evidence, or unsupported task controls blocks. | -| macOS desktop | macOS arm64 signed/notarized app with bundled 6.1.3 server/web. | Bundle version, signature, Gatekeeper, stapling, `/api/health.version`, update metadata. | Mixed bundle/runtime, failed readiness, signature, or metadata checks blocks stable publication. | +| macOS desktop | macOS arm64 signed/notarized app with bundled 6.1.4 server/web. | Bundle version, signature, Gatekeeper, stapling, `/api/health.version`, update metadata. | Mixed bundle/runtime, failed readiness, signature, or metadata checks blocks stable publication. | | Linux/Windows desktop | Unsigned preview artifacts only. | Cross-platform packaging workflows. | Not a supported stable install or update channel. | | Desktop SQLite/profile | Existing v5.2.5 workspace upgraded in place after a complete backup. | Data/profile counts, integrity check, startup normalization, board/runtime smoke. | Competing writers, unsafe filesystem, failed migration, or missing recovery evidence blocks acceptance. | diff --git a/docs/V6-GA-CHECKLIST.md b/docs/V6-GA-CHECKLIST.md index c2cbeb96..c4b29739 100644 --- a/docs/V6-GA-CHECKLIST.md +++ b/docs/V6-GA-CHECKLIST.md @@ -1,13 +1,24 @@ # Veritas Kanban v6 GA Checklist -This checklist contains the active stable-release gate for Veritas Kanban -6.1.3 and retains the completed 6.1.2, 6.1.1, 6.1.0, and 6.0.2 evidence below. +This checklist contains the completed stable-release gate for Veritas Kanban +6.1.4 and retains the completed 6.1.3, 6.1.2, 6.1.1, 6.1.0, and 6.0.2 evidence below. Command results, platform details, workflow links, limitations, and artifact hashes belong in [v6 Release Candidate Evidence Packet](V6-RC-EVIDENCE-PACKET.md). -Documentation freshness: 2026-08-30 for Veritas Kanban 6.1.3. +Documentation freshness: 2026-09-02 for Veritas Kanban 6.1.4. -## 6.1.3 Release Gate +## 6.1.4 Release Gate + +- [x] Release tracker [#1307](https://github.com/BradGroux/veritas-kanban/issues/1307) and publication-boundary fix [#1308](https://github.com/BradGroux/veritas-kanban/pull/1308) are merged with focused security regression evidence. +- [x] Root, shared, server, web, CLI, MCP, desktop, and lockfile package metadata are exactly 6.1.4. +- [x] The production dependency audit passes the high-severity threshold with `fast-uri` 3.1.6, and 6.1.4 adds no API or database schema change. +- [x] Release PR [#1309](https://github.com/BradGroux/veritas-kanban/pull/1309) passed the full release matrix and merged as `36b5529050aeb5cabbbefa8ac90e43f5f02e04d5`. +- [x] Annotated tag `v6.1.4` peels to the release merge, and the live GitHub release body matches `docs/releases/v6.1.4.md`. +- [x] Desktop Release run [33672624733](https://github.com/BradGroux/veritas-kanban/actions/runs/33672624733) published the signed/notarized macOS DMG and ZIP, blockmaps, checksum sidecars, and updater metadata. +- [x] Homebrew tap PR [#55](https://github.com/BradGroux/homebrew-tap/pull/55) merged with cask version 6.1.4 and the verified published ZIP checksum. +- [x] The coordinated security fix is included in every supported 6.1.4 distribution surface; advisory disclosure remains owner-controlled. + +## Historical 6.1.3 Completed Release Gate - [x] Release tracker #1262 and its implementation dependencies are merged or have an evidence-backed disposition; only the final release matrix and @@ -225,7 +236,7 @@ recorded in the release candidate evidence packet. - [x] Codex app-server 0.145.0 passes exact generated schemas, disabled remote control, lifecycle, approval, event, completion, and deterministic fixtures. -- [x] Codex CLI and `@openai/codex-sdk 0.144.3` pass their provider-runtime, +- [x] Codex CLI and `@openai/codex-sdk 0.149.0` pass their provider-runtime, launch, tool, event, credential, and completion gates. - [x] Claude Code 2.1.218 passes bare-mode launch, permission, environment, stream, lifecycle, MCP, event, completion, and deterministic fixtures. diff --git a/docs/V6-RC-EVIDENCE-PACKET.md b/docs/V6-RC-EVIDENCE-PACKET.md index eef7221e..3f685556 100644 --- a/docs/V6-RC-EVIDENCE-PACKET.md +++ b/docs/V6-RC-EVIDENCE-PACKET.md @@ -1,17 +1,42 @@ # Veritas Kanban v6 Release Candidate Evidence Packet -This packet records the active Veritas Kanban 6.1.3 backlog release candidate and -retains historical evidence for the completed 6.1.2, 6.1.1, and 6.1.0 releases, the quarantined 6.0.0 prerelease, the 6.0.1 +This packet records the completed Veritas Kanban 6.1.4 security release and +retains historical evidence for the completed 6.1.3, 6.1.2, 6.1.1, and 6.1.0 releases, the quarantined 6.0.0 prerelease, the 6.0.1 stabilization release, and the 6.0.2 desktop recovery hotfix. It separates merged implementation, deterministic conformance, local runtime proof, signed publication, and Homebrew availability. -Veritas Kanban 6.1.3 is the supported stable v6 release. Do not use 6.0.0 for +Veritas Kanban 6.1.4 is the supported stable v6 release. Do not use 6.0.0 for installation or upgrade validation. -Documentation freshness: 2026-08-30 for the published Veritas Kanban 6.1.3 release. +Documentation freshness: 2026-09-02 for the published Veritas Kanban 6.1.4 release. -## 6.1.3 Backlog Release Candidate +## 6.1.4 Security Release + +| Field | Value | +| ------------------------- | --------------------------------------------------------------------------------------------------------------------------- | +| Release version | 6.1.4 | +| Release tracker | [#1307](https://github.com/BradGroux/veritas-kanban/issues/1307) | +| Security implementation | [PR #1308](https://github.com/BradGroux/veritas-kanban/pull/1308), merged as `82bab7fb91e97bdbc675d060bcd2c6abdfef3b51` | +| Release implementation | [PR #1309](https://github.com/BradGroux/veritas-kanban/pull/1309), merged as `36b5529050aeb5cabbbefa8ac90e43f5f02e04d5` | +| Version and compatibility | All maintained packages are 6.1.4; REST API remains `v1`; no database migration; valid 6.1.3 workspaces remain compatible | +| Security disposition | The coordinated fix is included in every supported 6.1.4 distribution surface; advisory disclosure remains owner-controlled | + +The full release CI run [33671382853](https://github.com/BradGroux/veritas-kanban/actions/runs/33671382853) passed build, lint/typecheck, workspace units, changed tests, critical-path coverage, security audit, CodeQL, gitleaks, Playwright, k6, the Docker runtime contract, and unsigned macOS, Linux, and Windows desktop artifacts. The annotated tag object `fed62cfac3386a3d9c59b2a3befa101e3d5cd19a` peels to the exact release merge `36b5529050aeb5cabbbefa8ac90e43f5f02e04d5`. + +The [v6.1.4 GitHub release](https://github.com/BradGroux/veritas-kanban/releases/tag/v6.1.4) was published on 2026-09-02 with a live body matching `docs/releases/v6.1.4.md`. Desktop Release run [33672624733](https://github.com/BradGroux/veritas-kanban/actions/runs/33672624733) completed successfully and published these maintained macOS assets: + +| Asset | Size | SHA-256 | +| --------------------------------------------- | ----------------: | ------------------------------------------------------------------ | +| `Veritas-Kanban-6.1.4-mac-arm64.dmg` | 272,002,960 bytes | `712af00b95d952b6c5b46642cff19b88d134fe7fe520ebe530bd580cb30dd83a` | +| `Veritas-Kanban-6.1.4-mac-arm64.zip` | 276,323,390 bytes | `83eb0dd50116058b975f22de2d96a5583a7a3cda6e2be6266e897ca895ff0672` | +| `Veritas-Kanban-6.1.4-mac-arm64.dmg.blockmap` | 282,204 bytes | `5dd2dd49c89d978e22c094bd48b893fbb81b5f0b101b5a854bf86f26b565208f` | +| `Veritas-Kanban-6.1.4-mac-arm64.zip.blockmap` | 287,599 bytes | `ad92a8b2c39c5dc769f65fff8d9027bf53ff4f785793f5e97e05e84a9f3e54a5` | +| `latest-mac.yml` | 530 bytes | `82665b85024579ef78a130c2ac71c2d82a389b140bf7a843c7fff0707a11cd54` | + +Homebrew tap [PR #55](https://github.com/BradGroux/homebrew-tap/pull/55) merged as `1b01aa1cfd463bb5d5a51e4395c1071c142bbd80`. The live cask reports 6.1.4 and pins the published ZIP checksum `83eb0dd50116058b975f22de2d96a5583a7a3cda6e2be6266e897ca895ff0672`. + +## Historical 6.1.3 Backlog Release Candidate | Field | Value | | --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | diff --git a/docs/V6-RELEASE-NOTES.md b/docs/V6-RELEASE-NOTES.md index 9362a39e..1c3fa908 100644 --- a/docs/V6-RELEASE-NOTES.md +++ b/docs/V6-RELEASE-NOTES.md @@ -1,10 +1,16 @@ -# Veritas Kanban 6.1.3 Release Notes +# Veritas Kanban 6.1.4 Release Notes -Veritas Kanban 6.1.3 adds governed file artifacts, provenance-aware execution, operator Run Access controls, and recurring automation activation. It also closes the August Apple-design audit and hardens concurrent storage and provider teardown paths. This is a backward-compatible patch release for 6.1.2 with additive REST contracts and one SQLite migration. +Veritas Kanban 6.1.4 is a focused security patch that binds pull-request publication to the managed task worktree and its captured Git state. It also updates the patched `fast-uri` override to 3.1.6. This release adds no API or database schema change and remains compatible with valid 6.1.3 workspaces. -> Veritas Kanban 6.0.0 remains a quarantined prerelease. Version 6.1.3 is the supported stable v6 release after its annotated tag, signed assets, updater metadata, and Homebrew cask are published and verified. +> Veritas Kanban 6.0.0 remains a quarantined prerelease. Version 6.1.4 is the supported stable v6 release after its annotated tag, signed assets, updater metadata, and Homebrew cask were published and verified. -## Backlog Outcomes And Traceability +## 6.1.4 Security And Compatibility + +Repository publication accepts only canonical Git branch names and requires durable authority for the exact task, managed worktree, configured repository and origin, source and base branches, and captured commit. Pushes publish the captured commit through isolated Git transport and fail closed when authority is absent, stale, or mismatched. Existing valid hierarchical branch names remain supported, and existing remote task branches may advance only by safe fast-forward. + +The public REST API remains `v1`. Version 6.1.4 adds no SQLite migration. Back up the complete stopped-writer workspace before upgrading and retain the backup until the upgraded runtime is accepted. + +## Historical 6.1.3 Backlog Outcomes And Traceability | Issue | Operational outcome | Pull request | | ---------------------------------------------------------------- | --------------------------------------------------- | ------------ | @@ -70,13 +76,13 @@ For a first installation: brew install --cask bradgroux/tap/veritas-kanban ``` -Manual installation uses the signed and notarized macOS arm64 DMG or ZIP from the [v6.1.3 release](https://github.com/BradGroux/veritas-kanban/releases/tag/v6.1.3). Back up the complete stopped-writer workspace before upgrading and keep the backup until the new runtime is accepted. +Manual installation uses the signed and notarized macOS arm64 DMG or ZIP from the [v6.1.4 release](https://github.com/BradGroux/veritas-kanban/releases/tag/v6.1.4). Back up the complete stopped-writer workspace before upgrading and keep the backup until the new runtime is accepted. ## Breaking Changes And Migration Warnings -The public REST API remains `v1`, and the new routes and schemas are additive. SQLite migration 34 creates governed work-product artifact storage and indexes. Upgrading from 6.1.2 does not rewrite existing Work Product rows, but an older binary must not open the migrated workspace. +The public REST API remains `v1`, and 6.1.4 adds no database migration. Version 6.1.3 introduced SQLite migration 34 for governed work-product artifact storage and indexes. Upgrading directly from 6.1.2 does not rewrite existing Work Product rows, but an older binary must not open the migrated workspace. -Rollback is restore-first. Stop every writer, reinstall 6.1.2 only when using an unmigrated workspace, and otherwise restore the complete stopped-writer 6.1.2 backup. Never copy an older database over a running instance. +Rollback from 6.1.4 to the complete 6.1.3 application bundle does not require a schema rollback. For rollback to 6.1.2 or earlier, stop every writer and restore the matching complete stopped-writer backup. Never copy an older database over a running instance. ## Known Limitations diff --git a/docs/V6-UPGRADE-INSTALL-ADMIN-GUIDE.md b/docs/V6-UPGRADE-INSTALL-ADMIN-GUIDE.md index df14152e..4c539c3a 100644 --- a/docs/V6-UPGRADE-INSTALL-ADMIN-GUIDE.md +++ b/docs/V6-UPGRADE-INSTALL-ADMIN-GUIDE.md @@ -1,15 +1,15 @@ # Veritas Kanban v6 Upgrade, Install, Remote, And Admin Guide -This is the release-facing operator guide for Veritas Kanban 6.1.3. The +This is the release-facing operator guide for Veritas Kanban 6.1.4. The detailed provider commands live in [Agent Providers](AGENT-PROVIDERS.md), the machine-readable support contract is summarized in [Harness Compatibility](HARNESS-COMPATIBILITY.md), and Buzz relay setup lives in [Buzz Integration](BUZZ-INTEGRATION.md). -Documentation freshness: 2026-08-30 for Veritas Kanban 6.1.3. +Documentation freshness: 2026-09-02 for Veritas Kanban 6.1.4. -Do not install 6.0.0. It is retained as a quarantined prerelease. Version 6.1.3 -is the supported stable v6 release and supersedes 6.1.2. +Do not install 6.0.0. It is retained as a quarantined prerelease. Version 6.1.4 +is the supported stable v6 release and supersedes 6.1.3. ## Fresh Mac Desktop Install @@ -21,8 +21,8 @@ brew install --cask veritas-kanban ``` Manual installation uses -`Veritas-Kanban-6.1.3-mac-arm64.zip` from the -[v6.1.3 GitHub release](https://github.com/BradGroux/veritas-kanban/releases/tag/v6.1.3). +`Veritas-Kanban-6.1.4-mac-arm64.zip` from the +[v6.1.4 GitHub release](https://github.com/BradGroux/veritas-kanban/releases/tag/v6.1.4). Move `Veritas Kanban.app` into `/Applications`, launch it normally, and verify Settings -> Maintenance before enabling an agent or external integration. @@ -30,7 +30,7 @@ For a new board: 1. Choose Board Only unless agent execution is required immediately. 2. Create the local admin password and retain the recovery key securely. -3. Confirm `/api/health` reports version 6.1.3. +3. Confirm `/api/health` reports version 6.1.4. 4. Create a governed backup before adding external credentials or relay mappings. @@ -58,14 +58,14 @@ equivalent v5.2.5 self-hosted workspace. preferred port are stopped before copying data. 5. Preserve the complete workspace, not only the SQLite file. Keep the backup through release acceptance. -6. Install v6.1.3 without replacing the workspace. +6. Install v6.1.4 without replacing the workspace. 7. Launch with the same profile. If setup appears for a populated database, choose **Use Existing Data**. Do not rerun file migration or restore over the populated database. 8. Wait for the exact-version readiness gate: ```bash - EXPECTED_VERSION=6.1.3 + EXPECTED_VERSION=6.1.4 pnpm desktop:wait:ready -- --expected-version "$EXPECTED_VERSION" ``` @@ -82,7 +82,7 @@ The public API remains `v1`. v6 adds provider, approval, lifecycle, tool, credential, compatibility, Buzz, and conformance records without requiring a new API mount. -Veritas Kanban 6.1.3 adds SQLite migration 34 for governed work-product +Veritas Kanban 6.1.4 adds no database migration. Veritas Kanban 6.1.3 added SQLite migration 34 for governed work-product artifacts. Upgrading from 6.1.2 creates the artifact table and indexes without rewriting existing work-product rows. Runtime-path normalization can still move legacy files into the configured canonical data root. Keep the stopped-writer @@ -138,7 +138,7 @@ flow, then enable its built-in profile in Settings -> Agents. | Buzz Agent | Build/install Buzz v0.4.24 `buzz-agent`; verify ACP identity `buzz-agent 0.1.0`. | `ANTHROPIC_API_KEY`, `OPENAI_COMPAT_API_KEY`, or `DATABRICKS_TOKEN`. | Disabled; no resume; only the system-owned `veritas-run` MCP bridge. | | Grok Build | Install v0.2.111; run `grok --version`. | Existing `GROK_HOME`, `XAI_API_KEY`, `GROK_CODE_XAI_API_KEY`, or `GROK_DEPLOYMENT_KEY`. | Disabled; dedicated `agent --no-leader ... stdio`; restrictive policy only. | | Codex CLI/app-server | Install the reviewed Codex CLI; run `codex login status`. App-server certification requires 0.145.0. | Existing Codex login or `OPENAI_API_KEY` where supported. | Workspace-write task sandbox; app-server plugins, apps, hooks, browser/computer tools, remote control, and unsandboxed shell command disabled. | -| Codex SDK | Installed with Veritas as `@openai/codex-sdk 0.144.3`. | Existing Codex login or `OPENAI_API_KEY`. | Shared manifest, sandbox, tool, event, and completion controls. | +| Codex SDK | Installed with Veritas as `@openai/codex-sdk 0.149.0`. | Existing Codex login or `OPENAI_API_KEY`. | Shared manifest, sandbox, tool, event, and completion controls. | | Claude Code | Install 2.1.218; run `claude --version` and `claude auth status`. | `ANTHROPIC_API_KEY`, `ANTHROPIC_AUTH_TOKEN`, Foundry, bounded Bedrock keys, or explicit Vertex credential file reference. | Disabled; `--bare`, `dontAsk`, strict MCP, credential scrubbing; no permission bypass. | | GitHub Copilot CLI | Install v1.0.74; run `copilot --version` and provider login. | `COPILOT_GITHUB_TOKEN`, `COPILOT_PROVIDER_API_KEY`, `COPILOT_PROVIDER_BEARER_TOKEN`, `GH_TOKEN`, or `GITHUB_TOKEN`. | Disabled; ACP public preview, remote/plugins/custom instructions/experimental features off. | | Hermes Agent | Install v2026.7.7.2; run `hermes --version`. | `HERMES_API_KEY` or the documented model-provider key. | Disabled; one-shot scripted execution. | diff --git a/docs/architecture/V6-AGENT-RUNTIME-CONTROL-PLANE.md b/docs/architecture/V6-AGENT-RUNTIME-CONTROL-PLANE.md index feada9fc..2e7701f6 100644 --- a/docs/architecture/V6-AGENT-RUNTIME-CONTROL-PLANE.md +++ b/docs/architecture/V6-AGENT-RUNTIME-CONTROL-PLANE.md @@ -1,6 +1,6 @@ # Veritas Kanban v6 Agent Runtime Control Plane -This document defines the supported v6.1.3 architecture for executable agent +This document defines the supported v6.1.4 architecture for executable agent harnesses and Buzz integration. It is the version-level composition of the individual contract documents for [ACP](ACP-PROVIDER-V1.md), @@ -9,7 +9,7 @@ individual contract documents for [tool control](TOOL-CONTROL-PLANE-V1.md), and [runtime hooks](RUNTIME-HOOK-V1.md). -Documentation freshness: 2026-08-30 for Veritas Kanban 6.1.3. +Documentation freshness: 2026-09-02 for Veritas Kanban 6.1.4. ## Authority Model @@ -35,7 +35,7 @@ owns signed delivery, not Veritas task or completion state. | `codex-app-server` | OpenAI Codex app-server 0.145.0 | Pinned JSON-RPC v2 stdio schemas | Thread/turn lifecycle, streamed items, exact provider requests, remote control and unsandboxed shell method disabled | | `claude-code` | Claude Code 2.1.218 | Supervised bare-mode stream-json process | System-owned arguments, static permissions, credential scrubbing, bounded JSONL, authoritative result required | | `codex-cli` | OpenAI Codex CLI | One-shot JSON process | Existing task transport plus v6 launch, tool, credential, event, supervisor, and completion contracts | -| `codex-sdk` | `@openai/codex-sdk 0.144.3` | In-process SDK stream | Existing SDK session transport plus the shared v6 contracts | +| `codex-sdk` | `@openai/codex-sdk 0.149.0` | In-process SDK stream | Existing SDK session transport plus the shared v6 contracts | | `hermes-cli` | Hermes Agent v2026.7.7.2 | One-shot process | No resume; unsupported conversation controls fail closed | | `openclaw` | OpenClaw v2026.6.11 | Gateway `/tools/invoke` | Remote task session with explicit gateway policy and capability evidence | | Buzz communication adapter | Buzz v0.4.24 relay/community | Signed Nostr HTTP and WebSocket | Channel mapping, replay, identity, definition import, and external workflow-trigger evidence only |