This release includes 3 breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
ReleasePort's take
Light signal`council init` now mandates sudo privileges and automatically seeds the primary council bench.
Why it matters: Requires sudo for initialization; affects any workflow using `council init`. Update scripts to include elevated permissions before version v0.11.5 adoption.
Summary
AI summaryPrimary council initialization requires human seeding and vetoes must be resolved via Telegram IDs.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Primary-council convene fails closed until human-seeded. Primary-council convene fails closed until human-seeded. Source: granite4.1:30b@2026-07-19-audit Confidence: low |
— |
| Breaking | High |
`council init` now requires sudo and seeds the primary council bench. `council init` now requires sudo and seeds the primary council bench. Source: llm_adapter@2026-07-19 Confidence: high |
— |
| Breaking | Medium |
Raw bench add/rm of the primary council is refused. Raw bench add/rm of the primary council is refused. Source: granite4.1:30b@2026-07-19-audit Confidence: low |
— |
| Feature | Low |
Veto principal must resolve to human or Telegram ID mapping. Veto principal must resolve to human or Telegram ID mapping. Source: granite4.1:30b@2026-07-19-audit Confidence: low |
— |
Full changelog
Sudo-gated one-time council init seeds the primary council bench (roster+chair+threshold+veto principal), sealed on the gate-proof rail and hash-chained in lineage.jsonl. Primary-council convene now fails closed until human-seeded; raw bench add/rm of the primary council refused. Veto principal must resolve (human: -> paired Telegram id, or tg:).
Breaking Changes
- `council init` now requires human seeding via sudo gate; raw bench add/rm of the primary council is refused.
- Primary-council convene fails closed until seeded.
- Veto principal must be resolved to a paired Telegram ID (human: -> tg:) or explicit tg: format.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About 5dive
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]