Skip to content

5dive

v0.11.9 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

agent-runtime agentic-engineering agentic-loops agents ai-agents ai-assistant
+14 more
ai-coding-assistant ai-tools antigravity autonomous-agents claude claude-code codex codex-cli coding-agent loop-engineering multi-agent openclaw self-hosted zero-human-company

Affected surfaces

auth breaking_upgrade

ReleasePort's take

Light signal
editorial:auto 7d

The Council CLI now restricts veto capability to the genesis principal and mandates authentication via tap for exercise.

Why it matters: Affects only the genesis principal; authenticated tap required to enforce veto, altering prior unrestricted behavior.

Summary

AI summary

Authenticated founder veto enforcement and tamper protection for The Council CLI.

Changes in this release

Security High

Nonce-binding (vetoNonceDigest + executeAfter) sealed into canonicalTranscript for tamper detection.

Nonce-binding (vetoNonceDigest + executeAfter) sealed into canonicalTranscript for tamper detection.

Source: granite4.1:30b@2026-07-19-audit

Confidence: low

Security High

Forged --veto-by flags are refused and logged, causing exit code 9.

Forged --veto-by flags are refused and logged, causing exit code 9.

Source: granite4.1:30b@2026-07-19-audit

Confidence: low

Breaking High

CLI now only OFFERS a veto to the genesis principal; EXERCISE requires authenticated tap.

CLI now only OFFERS a veto to the genesis principal; EXERCISE requires authenticated tap.

Source: llm_adapter@2026-07-19

Confidence: high

Feature Medium

Two-tier veto hold period of 15 minutes followed by a 48-hour posthoc window.

Two-tier veto hold period of 15 minutes followed by a 48-hour posthoc window.

Source: granite4.1:30b@2026-07-19-audit

Confidence: low

Feature Low

Inclusive expiry boundary included in veto logic.

Inclusive expiry boundary included in veto logic.

Source: granite4.1:30b@2026-07-19-audit

Confidence: low

Full changelog

Authenticated founder veto for The Council: CLI can only OFFER a veto to the genesis principal; EXERCISE is an authenticated tap. Nonce-binding (vetoNonceDigest + executeAfter) sealed INTO canonicalTranscript so the re-seal tamper check covers it; forged --veto-by refused+logged (exit 9); two-tier hold(15m)/posthoc(48h); inclusive expiry boundary. Verified: 16/16 veto e2e incl. wrapper-swap-refused (twice back-to-back), 80 engine, CI green. Descends main with DIVE-1492 (brand-floor) preserved.

Security Fixes

  • Forged --veto-by flag is now refused and logged (exit code 9).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track 5dive

Get notified when new releases ship.

Sign up free

About 5dive

All releases →

Related context

Earlier breaking changes

  • v0.11.22 council amend now requires constitutional-class motion for constitution changes
  • v0.11.5 Raw bench add/rm of the primary council is refused.
  • v0.11.5 `council init` now requires sudo and seeds the primary council bench.
  • v0.10.7 Changes delegated-push grant to be BUILDER-SCOPED, limiting push permissions.

Beta — feedback welcome: [email protected]