From df027269227d4b5bcf9e0c381d44fb94085771d0 Mon Sep 17 00:00:00 2001 From: grishencorp Date: Wed, 30 Sep 2026 21:05:36 -0300 Subject: [PATCH] Record verified 1.2.0 distribution and adoption --- AI.md | 2 +- README.md | 2 +- docs/action-control/README.md | 2 +- docs/component-maturity.md | 7 ++- docs/getting-started/README.md | 5 +++ docs/getting-started/adopting-1.2.md | 3 +- docs/release-channels.md | 20 ++++----- docs/releases/1.2.0-preparation.md | 5 ++- .../stable1-2-distribution-20260930.md | 43 +++++++++++++++++++ docs/stability.md | 8 ++-- 10 files changed, 75 insertions(+), 22 deletions(-) create mode 100644 docs/releases/stable1-2-distribution-20260930.md diff --git a/AI.md b/AI.md index 11c04d72..3e8cf64b 100644 --- a/AI.md +++ b/AI.md @@ -2,7 +2,7 @@ AgentPlat is an open-source TypeScript framework for persistent human-agent collaboration, with shared artifacts, human approvals and controlled execution on your infrastructure. -AgentPlat Agent Rooms provide the collaboration workspace. AgentPlat Collective Runtime and AgentPlat Agent Mesh add planning and distributed coordination when needed. AgentPlat 1.1.0 is published under npm `latest`, with compatibility governed by `docs/stability.md`; source availability, registry distribution and operational evidence must be checked separately. +AgentPlat Agent Rooms provide the collaboration workspace. AgentPlat Collective Runtime and AgentPlat Agent Mesh add planning and distributed coordination when needed. AgentPlat 1.2.0 is published under npm `latest`, with compatibility governed by `docs/stability.md`; source availability, registry distribution and operational evidence must be checked separately. - Canonical repository: https://github.com/Agentplat/agentplat - Website: https://agentplat.com diff --git a/README.md b/README.md index 9218dd24..75280b83 100644 --- a/README.md +++ b/README.md @@ -8,7 +8,7 @@ AgentPlat is an open-source TypeScript framework for persistent human-agent coll [Website](https://agentplat.com) · [Documentation](https://doc.agentplat.com) · [GitHub](https://github.com/Agentplat/agentplat) -> AgentPlat **1.1.0** is available on npm under `latest`, with opt-in governed agent autonomy and compatible instruction-driven work. See the [verified distribution record](docs/releases/stable1-1-distribution-20260929.md), [1.1 adoption guide](docs/getting-started/adopting-1.1.md), [stability contract](docs/stability.md) and [production guide](docs/production.md). +> AgentPlat **1.2.0** is available on npm under `latest`, adding opt-in standalone governed actions while preserving existing behavior. See the [verified distribution record](docs/releases/stable1-2-distribution-20260930.md), [1.2 adoption guide](docs/getting-started/adopting-1.2.md), [stability contract](docs/stability.md) and [production guide](docs/production.md). ## A concrete use case diff --git a/docs/action-control/README.md b/docs/action-control/README.md index 4dfd49d1..b1ff9d67 100644 --- a/docs/action-control/README.md +++ b/docs/action-control/README.md @@ -2,7 +2,7 @@ **Status:** additive, opt-in source profile; qualification passed in an isolated checkout on 2026-09-30. Introduced by the coordinated 1.2.0 release; consult the release record for -publication status. Operational obligations and release +publication status ([verified distribution](../releases/stable1-2-distribution-20260930.md)). Operational obligations and release steps remain explicit; no production-scale or universal external guarantee is claimed. This profile supports hosts such as The Agent Control without requiring Agent Rooms. diff --git a/docs/component-maturity.md b/docs/component-maturity.md index b2565ef9..3a7fb018 100644 --- a/docs/component-maturity.md +++ b/docs/component-maturity.md @@ -2,8 +2,10 @@ This is the editorial entry point for adoption status. Source availability, registry distribution, executable checks and operational evidence answer -different questions. None implies another. The source checkout prepares the unpublished 1.1.0 candidate, including optional -Jev. The verified 1.0.0 distribution remains under npm `latest`; see the [distribution record](releases/stable1-distribution-20260922.md). The [stability contract](stability.md) governs API compatibility independently of operational evidence. +different questions. None implies another. All 66 packages are published at 1.2.0 +under latest; see the [distribution record](releases/stable1-2-distribution-20260930.md). +The [stability contract](stability.md) governs API compatibility independently of +operational evidence. ## Source and integration map @@ -15,6 +17,7 @@ Jev. The verified 1.0.0 distribution remains under npm `latest`; see the [distri | Collective Runtime / planning | Public local collective and opt-in coordination controllers | `example:collective`, capability and evidence catalog verifiers | Frozen baseline separates source completion from empirical and operational validation | | Agent Mesh | Mesh, crypto, protocol, HTTP and PostgreSQL adapters | `example:mesh-multiprocess`, Mesh conformance checks | Four-peer example is bounded; deployment owns key custody, transport and membership | | Inference Control / Trust | Opt-in public controls and explicit integration subpaths | Inference-control and Trust scenario verifiers | Direct calls outside the integration path are not controlled; configure policies and assessor inputs | +| Standalone governed actions | Optional exact-target approval, transactional budgets/fences and PostgreSQL stores | `verify:action-control`, independent registry consumers | Bounded software evidence; trusted host ports, destination guarantees and tenant-state scaling remain deployment obligations | | Agent Morphogenesis | Opt-in Collective Runtime composition with host persistence | Existing Morphogenesis release/readiness verifiers | Signed Beta 1 local/staging profile only; not general production readiness or security certification | | A2A / Agent Registry | Opt-in A2A 1.0 client/server, registry and PostgreSQL; Room/Mesh/Morphogenesis bridges | `test:a2a`, `example:a2a`, `verify:a2a-consumer` | Local SDK/PostgreSQL integration evidence; host supplies identity, execution owners and network policy | | Memory, tools, events, audit and auth | Public contracts and package-specific adapters | Package tests and public consumer checks | In-memory implementations are not durable; choose adapters and define retention, identity and delivery | diff --git a/docs/getting-started/README.md b/docs/getting-started/README.md index c798c195..63365077 100644 --- a/docs/getting-started/README.md +++ b/docs/getting-started/README.md @@ -28,3 +28,8 @@ is a separate, pending usability evaluation. ## Upgrading to 1.1 See [Adopting AgentPlat 1.1.0](adopting-1.1.md) to keep instruction-driven work or opt into governed purpose execution. + +## Upgrading to 1.2 + +See [Adopting AgentPlat 1.2.0](adopting-1.2.md) for optional standalone action +approvals, reservations, revocation and recovery. Existing behavior stays configured. diff --git a/docs/getting-started/adopting-1.2.md b/docs/getting-started/adopting-1.2.md index ff32f28c..1a87ce45 100644 --- a/docs/getting-started/adopting-1.2.md +++ b/docs/getting-started/adopting-1.2.md @@ -1,6 +1,7 @@ # Adopting AgentPlat 1.2.0 -Status: release candidate; install from npm only after verified distribution. +Status: published and verified on 2026-09-30. All 66 packages are available at +1.2.0 under latest; see the [distribution record](../releases/stable1-2-distribution-20260930.md). 1. Upgrade the AgentPlat packages your application uses together to 1.2.0 and keep a lockfile. Existing applications retain their configured behavior. diff --git a/docs/release-channels.md b/docs/release-channels.md index cc9325ef..17ebaf9b 100644 --- a/docs/release-channels.md +++ b/docs/release-channels.md @@ -1,24 +1,24 @@ # Release channels -AgentPlat uses one fixed version per coordinated release cohort. The verified -1.0.0 cohort contains 65 published packages. **1.0.0** is -published under npm `latest`; it replaces the unpublished beta.10 candidate. -See the [verified distribution record](releases/stable1-distribution-20260922.md). +AgentPlat uses one fixed version per coordinated release cohort. **1.2.0** is +published under npm latest for all 66 coordinated packages; see the +[verified distribution record](releases/stable1-2-distribution-20260930.md) and +[adoption guide](getting-started/adopting-1.2.md). -The source checkout prepares **1.1.0 with 66 publishable packages**, adding the -optional `@agentplat/assessor-typesafe` adapter. This candidate is not published; -see [preparation and upgrade notes](releases/1.1.0-preparation.md). Jev is installed -only by applications that choose it. The verified npm tag remains unchanged. +The historical 1.0.0 cohort contained 65 packages. Version 1.1 added optional Jev, +and 1.2 adds opt-in standalone action controls without adding package names. +Jev remains installed only by applications that choose it. Source availability, +distribution and operational maturity remain separate evidence boundaries. Stable 1.x releases follow the [stability contract](stability.md). Prereleases use `next` and must never promote `latest`. Stable promotion requires successful public checks, exact artifact verification, reference integration validation, and clean registry consumers for the entire coordinated release. -After the 1.0.0 distribution record is verified, install exact versions: +Install exact coordinated versions: ```sh -pnpm add @agentplat/framework@1.0.0 @agentplat/sessions@1.0.0 +pnpm add @agentplat/framework@1.2.0 @agentplat/sessions@1.2.0 ``` See the [production and migration guide](production.md). Historical observations diff --git a/docs/releases/1.2.0-preparation.md b/docs/releases/1.2.0-preparation.md index 1ff9c0cd..a26de0a6 100644 --- a/docs/releases/1.2.0-preparation.md +++ b/docs/releases/1.2.0-preparation.md @@ -1,7 +1,8 @@ # AgentPlat 1.2.0 — release preparation -Status: owner-authorized publication in progress. The candidate preserves the -66-package coordinated cohort and targets `latest`. It is not yet a registry release. +Status: published and verified on 2026-09-30. All 66 coordinated packages are +available at 1.2.0 under latest. See [the distribution record](stable1-2-distribution-20260930.md). +The procedure below records preparation and release gates. ## Scope diff --git a/docs/releases/stable1-2-distribution-20260930.md b/docs/releases/stable1-2-distribution-20260930.md new file mode 100644 index 00000000..a7d5cf00 --- /dev/null +++ b/docs/releases/stable1-2-distribution-20260930.md @@ -0,0 +1,43 @@ +# AgentPlat 1.2.0 distribution — 2026-09-30 + +All **66 coordinated packages** are published at **1.2.0**, with npm `latest` +aligned. Date uses America/Montevideo. Existing applications keep their defaults; +standalone governed external actions are explicitly opt-in. + +The [release workflow](https://github.com/Agentplat/agentplat/actions/runs/36791383517) +completed successfully from source +[`5309bd3e15dae06f3aad3333d97d53dc7bdb495b`](https://github.com/Agentplat/agentplat/tree/5309bd3e15dae06f3aad3333d97d53dc7bdb495b), +integrated through [PR #202](https://github.com/Agentplat/agentplat/pull/202). +The [dry-run](https://github.com/Agentplat/agentplat/actions/runs/36789053780) +passed first. The publication artifact manifest was byte-identical to the dry-run: +`sha256-K61f3vF9OudcR4RCDS2JBUWH/7gsRqh7fsZee9kHhtA=`. + +Preparation, owner-only protected deployment approval, publication and final +verification passed. Exact-artifact review checked all 66 archives before approval. +Registry verification covered tarball bytes, npm ECDSA signatures, source provenance +fields and tags. Independent consumers passed the new action-control exports/types, +portable and PostgreSQL profiles, and npm under Node 22. A separate local verification +confirmed registry bytes, signatures, provenance and latest for the same cohort. + +The first verification query could not see `@agentplat/interop-postgres@1.2.0`. +After the version/tag became visible, only the failed verification job was rerun +in the same original release. Preparation and publication were not repeated. + +## Adoption + +Update the AgentPlat packages you use together to 1.2.0; installing all 66 is +unnecessary. Start with [the adoption guide](../getting-started/adopting-1.2.md) +and [standalone action integration](../action-control/integration.md). + +For The Agent Control, use the public optional approval/admission/effect contracts +and PostgreSQL subpaths. Identity, business policy, exact request display, trusted +quotes/facts, connectors and credential custody remain ACL responsibilities. +Existing installations do not invoke the optional migrations automatically. + +The release also patches locked production dependency advisories through the existing +override mechanism. No audit exception, npm write token or protection waiver was added. + +These are bounded software/distribution checks, not model-quality, production-scale +or universal external exactly-once guarantees. Provenance field checks are not an +independent full Sigstore certificate/transparency-log verifier. Unsupported destinations +cannot gain atomic conditional-write guarantees from capability declarations alone. diff --git a/docs/stability.md b/docs/stability.md index 8cb20eff..139bfb7d 100644 --- a/docs/stability.md +++ b/docs/stability.md @@ -1,13 +1,13 @@ # Stability and maintenance -Version 1.0.0 is the first coordinated stable release, published on npm under -`latest`. This policy applies to published 1.x versions. See the +Version 1.0.0 was the first coordinated stable release. The current latest +release is [1.2.0](releases/stable1-2-distribution-20260930.md). This policy applies to published 1.x versions. See the [verified distribution record](releases/stable1-distribution-20260922.md). ## Public compatibility contract -The 65 packages published in 1.0.0 share one release version. The 1.1.0 -candidate adds the optional Jev adapter for a 66-package coordinated cohort. The source catalog may include unpublished packages under a separate +The 65 packages published in 1.0.0 share one release version. Version 1.1.0 +added optional Jev; 1.2.0 retains that 66-package coordinated cohort. The source catalog may include unpublished packages under a separate source-only release profile; those are not part of the npm compatibility surface until admitted to a coordinated release. The supported API consists of their package.json export entry points, exported