This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summaryUpdates P4-3, P4-5, and documented across a mixed release.
Full changelog
Tech-debt elimination + provider honesty + regression hardening
- Dead-stub removal (P4-3) (
loki-ts/src/runner/autonomous.ts): the Bun
runner carried logStub/noopCouncil/stubProvider fallbacks for modules that all
exist and conform. These were unreachable dead code that silently degraded to
wrong results if ever hit. Replaced with a fail-fastrequireModule()(a
missing load-bearing module now errors loudly at resolution time instead of
producing a wrong build), while genuine runtime-error fallbacks are preserved. - Antigravity de-listed (P4-5): "Antigravity CLI" was advertised across docs
as an upcoming Loki provider but had zero implementation, and was misattributed
to Anthropic (it is Google's product). Removed from all provider tables/lists
(README, SKILL, CLAUDE, wiki, docs/INSTALLATION). Honest competitor references
in docs/COMPARISON.md are retained. - Bun semantic-findings consumer wired (
loki-ts/src/runner/build_prompt.ts):
the Bun semantic-test gate persisted.loki/quality/semantic-findings.txtbut
nothing on the Bun route read it (a writer-with-no-reader). build_prompt.ts now
reads and injects those severity-tagged findings into the next-iteration prompt,
independent of gate-failures.txt, byte-parity with the bash route. Absent/empty
injects nothing. - Policy-context quoting fix (
autonomy/run.shcheck_policy):${2:-{}}
brace-eating expansion turned a non-empty JSON context into invalid JSON
({"a":1}}), so the policy engine received garbage and returned DENY every
iteration when a.loki/policies.json/.yamlexisted (and made the P3-3
approval-wait unreachable on the live path). Fixed to a split default yielding
valid{}; non-empty contexts now pass through unchanged. Users with no policy
file are unaffected. - Compliance snapshot scheduler (P3-11, optional) (
src/audit/compliance-scheduler.js):
a default-disabled helper that periodically persists a compliance snapshot from
the real audit chain (honest empty-state, never a fabricated verdict). Ships as
a tested helper; not yet auto-invoked (documented). - Regression hardening: added guards for the v7.51-v7.54 features, notably
tests/test-no-deprecated-codex-flag.sh(fails if any livecodex exec --full-autois reintroduced), plus coverage-artifact, evidence-gate-consumer,
approval-phase-gate, and semantic-gate-bash-route regression tests.
Gates: local-ci 83/83, full pytest + bun test (1009 Bun tests) + bash/Bun parity
green, 3-reviewer council unanimous APPROVE (after a round that correctly caught a
self-contradicting code comment, now fixed).
Breaking Changes
- Removed unreachable logStub/noopCouncil/stubProvider fallbacks in `loki-ts/src/runner/autonomous.ts`; missing load‑bearing modules now cause an error at require time instead of silent incorrect builds.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Loki Mode
Multi-agent autonomous SDLC framework. Spec to deployed app. PRD, GitHub issue, OpenAPI/JSON/YAML, or one-line brief. 5 AI providers, 11 quality gates.
Related context
Related tools
Beta — feedback welcome: [email protected]