This release includes 1 security fix for security teams reviewing exposed deployments.
Published 26d
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai-agents
aider
anthropic
autonomous
ci-cd
claude
+13 more
cline
code-review
devops
gemini
github-action
github-issues
loki-mode
multi-agent
openai-codex
openapi
pull-request-review
sdlc
spec-driven-development
Affected surfaces
auth
Summary
AI summaryUnrecognized trust gate status now maps to "inconclusive" to prevent fake‑green verification.
Full changelog
Trust: unknown quality-gate status can no longer read green
- Unrecognized gate status normalized to inconclusive (
autonomy/lib/proof-generator.py):
_norm_gate_statusreturned an unrecognized gate status verbatim (e.g. a gate
emitting "blocked" or a custom token). The Evidence Receipt headline only
checks gate status against "passed" and "failed", so such a value matched
neither and silently vanished - a gate that did not pass would not count
against a VERIFIED headline (a fake-green vector). An unrecognized status now
maps to "inconclusive", which lands the gate in honesty.degraded and forces an
honest non-green headline. Known statuses are unchanged. Regression test added.
Breaking Changes
- _norm_gate_status: unrecognized gate statuses (e.g., "blocked", custom tokens) now normalized to "inconclusive" instead of being returned verbatim
Security Fixes
- Normalization of unknown gate status to inconclusive prevents fake‑green verification vectors
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Loki Mode
Multi-agent autonomous SDLC framework. Spec to deployed app. PRD, GitHub issue, OpenAPI/JSON/YAML, or one-line brief. 5 AI providers, 11 quality gates.
Related context
Related tools
Beta — feedback welcome: [email protected]