This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryCloses compound-object residual vectors by refusing to strip destructive verbs when production/customer targets appear.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Expands floor to block 'drop table' and 'truncate' commands. Expands floor to block 'drop table' and 'truncate' commands. Source: granite4.1:30b@2026-07-19-audit Confidence: low |
— |
| Bugfix | Medium |
Prevents stripping destructive verbs in compound-object residual vectors. Prevents stripping destructive verbs in compound-object residual vectors. Source: llm_adapter@2026-07-19 Confidence: low |
— |
| Refactor | Low |
Biases system to over-elevate ambiguous cases for safety. Biases system to over-elevate ambiguous cases for safety. Source: granite4.1:30b@2026-07-19-audit Confidence: low |
— |
Full changelog
Closes the compound-object residual vectors left by DIVE-1481. The internal-ops carve-out now REFUSES to strip a destructive verb when an external prod/customer target appears anywhere in the ask, so a coordinated or passive compound (e.g. 'delete the board and the production database', 'wipe the board then delete the prod customer records') keeps the verb in the residual, trips the tier-2 floor, and stays hard-human. Floor widened: 'drop <..> table' + 'truncate'. Biased to over-elevate (the safe direction); purely-internal asks still downgrade to lead review. Known inherent limit (keyword heuristic): a prod object named with a noun outside the vocab can still downgrade - lead-reviewer is the backstop. (DIVE-1487)
Security Fixes
- Closes compound-object residual vectors (DIVE-1481) by preventing verb removal when production or customer targets are present, widening floor to include 'drop table' and 'truncate'.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About 5dive
All releases →Related context
Related tools
Earlier breaking changes
- v0.11.22 council amend now requires constitutional-class motion for constitution changes
- v0.11.9 CLI now only OFFERS a veto to the genesis principal; EXERCISE requires authenticated tap.
- v0.11.5 Raw bench add/rm of the primary council is refused.
- v0.11.5 `council init` now requires sudo and seeds the primary council bench.
- v0.10.7 Changes delegated-push grant to be BUILDER-SCOPED, limiting push permissions.
Beta — feedback welcome: [email protected]