This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Affected surfaces
Summary
AI summaryinstall.sh now pins main to a specific commit SHA and separates cache skew from tampered‑mirror errors.
Full changelog
install.sh resolves main to ONE immutable commit sha and fetches the bundle, its .sha256 and every managed asset from raw//, so the two objects can no longer come from different CDN cache generations. The checksum guard is byte-for-byte unchanged; the mismatch message now separates pinned bad-bytes from unpinned cache skew instead of alleging a tampered mirror.
Verified in a live post-release window: unpinned /main served the previous bundle (83e57a92) beside the new checksum (a50fb089) across the whole window, while the pinned tree stayed self-consistent on every poll. (DIVE-1977)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About 5dive
All releases →Related context
Related tools
Earlier breaking changes
- v0.11.22 council amend now requires constitutional-class motion for constitution changes
- v0.11.9 CLI now only OFFERS a veto to the genesis principal; EXERCISE requires authenticated tap.
- v0.11.5 Raw bench add/rm of the primary council is refused.
- v0.11.5 `council init` now requires sudo and seeds the primary council bench.
- v0.10.7 Changes delegated-push grant to be BUILDER-SCOPED, limiting push permissions.
Beta — feedback welcome: [email protected]