Releases
Every Korvun release ships signed binaries for six platforms (Linux, macOS, Windows × x86-64, ARM64), and since v0.4.0 the desktop apps too: each artifact is covered by a cosign-signed checksum manifest, and each of the six headless archives also ships an SBOM; the desktop apps ship without one today. How to download and verify is in the install guide.
All releases live on GitHub: github.com/Sebastian197/korvun/releases
The story so far
| Release | What it brought |
|---|---|
| v0.16.1 | Current release — the Beta (patch) — a release of CURES with one new surface: korvun intent bind --grant ties a signed grant to an execution binding, so the attenuated delegation v0.16.0 shipped implemented, tested and unreachable becomes something an operator can put in an execution's path — and a start under it seals config_generation 0, no clause consulted, with a grant_chain naming the grant. The grave cure: four writers paid the retention cadence AFTER their own commit and returned its error, so a durable write reported itself as a refusal — worst of all at the park, where the approval id was lost, the executor read a refusal and wrote a SECOND actions row while the PENDING one waited for a human nobody would tell. Plus SIX fichas closed — a deterministic purge error that was published as the only TRANSIENT class, GetApprovalByAction returning the driver's raw error where every sibling door answers with a named class, korvun approvals list hiding a row whose status fell outside the five it knows (corruption dressed as absence), a pending list that dropped the id it promised, a rejection painting an unminted receipt under a title that claims a sealed one, and the receipt's shape leaving TypeScript so shortening the minted id can no longer break the screen while six Go packages stay green — plus a FINDING no ficha described, a strict id judged in the store by one shared question at three doors, and a CI guard that keeps the Wails CLI pinned to its library. The director's own ficha about that finding, which saw the same symptom ON THE SCREEN, stays open: whether three server doors close its half is his adjudication, not a fact this release claims. Known limits, unsoftened: re-binding WITHOUT the flag still collides with the unique index, so there is no way back to the config clause from the command line; no command replaces or lists every binding of an (actor, channel); no external pass ran against this tag — no credits; and no real model has driven a delegation end to end. |
| v0.16.0 | the Beta (minor) — piece 3 whole: a verified NAME, a signed PURPOSE and a signed AUTHORITY behind every effect a model asks for. Every ingress door mints an opaque authenticated capability where its own authentication succeeds, and the coordinator turns it into signed identity evidence written in the same transaction as the action; an intent is a signed, versioned contract with its own lifecycle; authority grants are signed and can only attenuate, with budgets shared across a chain. Under a profile that asks for it — authority.mode: "strict", off by default — StartAuthorization is the durable commit boundary: it verifies the current evidence and scope, debits the intent and every grant, records the signed start proof and, for an approved request, claims its parameters, all at once, and only a committed start hands the coordinator an invocation capability. The approval document gains the AUTORIDAD block: who asked, under which contract, through which chain of principals, and the budget that remained WHEN THE REQUEST WAS PARKED — a signed snapshot verified on every read, not a live meter. It ships one BEHAVIOUR CHANGE an operator must read first: with strict mode on, read_file, http_fetch and webhook_call become closed world and start only under terms that list the resources, data tags and destinations they may touch — and the scope belongs to the INTENT, so any operation without a registered analyzer refuses too. A non-strict boot over an activated profile is refused by name, printing the digest needed to boot it. Known issues are in the notes, unsoftened: no public door ties a signed grant to an execution binding, so delegation is implemented and tested but not reachable from the CLI; the v0.15.2 filings all stay open; and no external pass ran against this tag — no credits — so no adversarial reading, internal or external, covers the tree it names. |
| v0.15.1 | the Beta (patch) — the patch that cures the three P1 findings of the seventeenth external pass and narrows what the window may affirm. The approval claim now re-reads the purged parameters inside its own transaction and refuses when the purge did not hold; every cell the claim reads has one error class, a store that did not answer separated from a row that does not convert; webhook_call calls success only when the receiver answered 2xx, and a connection never obtained closes FAILED; the approvals doors and the console's /message answer only a loopback peer, by name and with no opt-in; a receipt seals a named mark instead of an empty reference when the approval row cannot be used, and receipt verify and ledger check fail such a receipt by name. In the window, only an answer the screen can prove is this action's paints an execution: the digest must be IDENTICAL to the one it sent, the receipt minted and the result a non-empty string, and a rejected answer carrying a field of the wrong type is refused whole. It also corrects what the project CLAIMED — the digest that travels from the window, the narration of the approvals ceremony, the SBOM promise narrowed to the six headless archives — and adds a guard so the five current-release claims must name the same release as releaseFacts.tag. Known issues are filed to v0.15.2 in the release notes, unsoftened — including that single consumption still yields a second run against a restore committed after the claim commits while the action is APPROVED, and that the re-read copy after a params_digest_mismatch says the window did not decide what it did decide. |
| v0.15.0 | the Beta (minor) — the human yes, in the window: the fifth stage of the Execution Trust Layer, and the one that brings approvals. They are opt-in: with approvals.enabled set, an irreversible action under a bounded ceiling PARKS as a request until a human decides it — in the desktop window or with the operator CLI — or until it expires (default TTL one hour), against the same store, the same belts and the same claim that consumes the stored parameters once — a consumption with two known limits in v0.15.0: a trigger restoring the parameters inside the claim's own transaction defeats it (fixed on master, ships in v0.15.1), and another connection writing them back after the claim commits, while the action is still APPROVED, followed by a second execute, runs the effect again (filed for v0.15.2). If the park itself fails, or the request's provenance cannot be resolved, it falls closed to the same denial. Without the setting that action is denied with approval_unavailable, as it has been since v0.13.0; no earlier release could park it or decide it. The request is read as a document, not a dialog: the digest printed in eight groups with the line that says a single changed character makes it another digest, the operation, the effect class spelled out (write_irreversible — irreversible, no documented undo), the literal parameters, the origin, the exact law that required the approval, and the expiry named twice — relative and absolute. Approve is ARMED by retyping the last six characters of the digest and is the small button; Reject is the large one and needs no ceremony. Approving executes EXACTLY what the digest seals, and the claim purges the stored parameters, within the same two limits; rejecting closes the parked action with its own sealed receipt and delivers nothing. Every decision leaves a signed receipt on the chain. Known issues are filed to v0.15.1 in the release notes, unsoftened — including that the class cures ship reviewed by one internal pass that never saw its own cures. |
| v0.14.0 | the Beta (minor) — the ledger and the verifiable receipts: the fourth stage of the Execution Trust Layer. Every terminal action outcome — denied, shadowed, succeeded or failed — leaves a canonical receipt signed with Ed25519 on an append-only hash chain, born in the SAME transaction as the outcome (atomicity holds INSIDE the store; an external effect completed just before a failed terminal close is a documented window until stage 6 — see the v0.14.0 erratum); raw results never touch the disk — digests only. The operator re-judges the book offline, each failure the ladder judges named (a receipt whose stored bytes do not parse is refused with the read error and no ladder name): korvun receipt verify, korvun ledger check (a forgery that leaves the profile inconsistent named at its first broken check, a receipt deleted from INSIDE the chain denounced by its hole with its position), and korvun receipt rotate-key — each era of the chain verifies with the key of its era. The limit is confessed in every public line: tamper-evident, never "immutable". Since R14 the confession names FOUR blind spots, three of them verified by execution — a tail cut, a chain re-signed with a key the attacker registered inside the profile, and a config pointed at another store — each needing an external anchor Korvun does not ship yet; the fourth, not executed, is a row whose lookup column changed storage class, read as absence by the reader that seeks it. Automatic crash-proof v4→v6 migrations; receipts exempt from the retention prune; ~1.25 ms per governed action under the 5 ms ceiling. Accepted through the forgery-hunt ceremony on the director's real profile. |
| v0.13.0 | The Beta (minor) — effects and per-action policy: the third stage of the Execution Trust Layer. Every operation carries a declared class on a consequence ladder with a total order (unknown ranks above critical — fail-closed); effect ceilings wake as attenuation's tenth dimension, judged by the same oracle-checked validator at the store, the CLI (--effect-ceiling) and the gate; every decision pins the exact law that took it (governance + effect registry, versioned); and under bounded authority the irreversible demands a human yes — dying with the honest approval_unavailable until the approval workflow ships. Receipts untouched by construction; automatic crash-proof v2→v4 migrations; the exterior byte-for-byte. Accepted through the ladder ceremony on the director's real profile. |
| v0.12.0 | The Beta (minor) — identity, intent and authority: the second stage of the Execution Trust Layer. Every recorded action knows WHO asked (a principal born from authenticated provenance — a forged sender can never mint the operator), under WHICH human intention and with HOW MUCH authority — which can only shrink: the attenuation wall (oracle-judged, property-tested, fuzzed in the permanent gate) rejects any widening delegation naming the dimension, and governs the operator too. First operator tool: korvun intent / korvun grant, every act leaving an identified receipt — refusals included. Zero new config; automatic crash-proof v1→v2 store migration; receipts stay byte-compatible. Accepted through the operator's ceremony on the director's real profile. |
| v0.11.0 | The Beta (minor) — the Action Kernel: the first stage of the Execution Trust Layer. Every tool action is born as a canonical envelope with a deterministic digest, gets an explainable decision recorded BEFORE any effect (shadow never executes — now with a receipt; hallucinated tools are denied with their rule; an unrecordable attempt fails closed) and leaves a durable, capped, self-managing record — with ZERO experience change, zero new config and one machine-enforced path to execution. Full toll ~1ms per call (ceiling 5ms); parsers fuzzed from birth. Approved by the director's manual pass: identical chat plus a real customs receipt read from his own profile. |
| v0.10.0 | The Beta (minor) — the honest desktop, and the new face. The chat never lies: protocol JSON can never reach a channel, the wait names who is actually thinking, and a dead request says so on screen with a retry at hand (a 60-second notice warns but never cuts on its own). The desktop grows its missing rooms: brain selection on New chat, a write-only Secrets panel over the OS keychain, an onboarding that speaks OpenAI-compatible and validates the chosen model, mouse deletion for canvas cables, and a model panel that blocks corruption shapes before Apply. Plus the A1 governed-K identity across the website, README, app icon and CLI banner — and a real routing defect (a masked fatal close code) found and fixed by the deflake work. Gated end to end by the Sixth Law and the director's bash: zero use-breakers. |
| v0.9.2 | The Beta (patch) — the four use-breaking findings of the exhaustive UX audit, fixed and hand-verified on the packaged build: canvas cables can be disconnected, a provider change clears the orphan warmup, the reload trail is logged and its cutover contract pinned, and model health reaches the UI (builder badge + chat warning). The first release under the sixth house law: design-first, and a manual pass over the packaged build gates every release. |
| v0.9.1 | The Beta (patch) — seven desktop fixes from the first field audit of the packaged app: the Builder loses its embedded token gate, learns the openai-compatible provider truthfully, desktop configs always carry the admin block, the canvas answers (model-drop hint, panel close paths), the desktop logs to a file, and the webhook channel gains its wizard breadcrumb. |
| v0.9.0 | The Beta — the universal model gateway: any OpenAI-compatible endpoint, cloud or local, becomes a first-class model by config alone — same policy engine, same declared-locality privacy, same governed tools (native tool calling included), with quota told apart from rate limits, redirects refused, and the API key never surfacing. Full changes are recorded in the GitHub release notes. |
| v0.8.0 | Governed memory closes the last beta piece: bounded notes through the governed memory_note tool, deliberate /recall of a session's tail, /notes for the operator. Full changes are recorded in the GitHub release notes. |
| v0.7.0 | The operator console + governed tools & skills — the Chat tab (takeover, sessions, direct chat), tri-state tool grants with shadow rehearsal, the network shield, markdown skills, native tool calling with an honest fallback. |
| v0.6.0 | The visual builder canvas — drag channels, brains, and models from a palette, validator-checked cables, the privacy exclusion drawn as a gray dashed cable, persona per brain, hot apply. |
| v0.5.0 | The generic webhook channel — POST JSON in, replies out to your URL; fail-closed Bearer auth, conversation identity, honest 503 on saturation. |
| v0.4.0 | Korvun Desktop — the gateway behind a native window: first-run onboarding, secrets in the OS keychain, the builder embedded. |
| v0.3.0 | The Discord channel — Gateway inbound with resume/reconnect, REST outbound, mentions blocked by default, a complete anti-loop family. |
| v0.2.0 | Resilience + the CLI — boot warmup for local models, generous per-attempt timeouts, retry with differentiated fallback; serve, config check, status. |
Release notes are published on each GitHub release — this page stays a map, not a mirror.