Skip to content

Keesan12/Martin-Loop

v0.3.4 Bugfix

This release fixes issues for SREs watching stability and regressions.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agent-runtime ai-agent-runtime ai-coding-agents ai-control-plane ai-governance ai-safety
+13 more
audit-trail budget-enforcement claude-code codex coding-agents control-plane governed-runtime llmops mcp model-context-protocol observability policy-as-code rollback

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Fixed run verification integrity classification, path policy safety, selector validation, OpenAI auth blocking, and MCP scope guidance.

Changes in this release

Bugfix Medium

Path policy fails closed on traversal and absolute patterns.

Path policy fails closed on traversal and absolute patterns.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Run verification emits explicit integrity verdict classes.

Run verification emits explicit integrity verdict classes.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Non-canonical run selectors now fail fast with guidance.

Non-canonical run selectors now fail fast with guidance.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

OpenAI hosted preflight blocks missing auth with actionable guidance.

OpenAI hosted preflight blocks missing auth with actionable guidance.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

MCP scope errors guide operators to valid alternatives.

MCP scope errors guide operators to valid alternatives.

Source: llm_adapter@2026-06-09

Confidence: high

Full changelog

Fixed

  • Allow/deny path policy now fails closed on traversal and absolute patterns - governed preflight/run rejects unsafe --allow-path and --deny-path values before execution.
  • Run verification now emits explicit integrity verdict classes - runs verify classifies receipt problems as tampered_payload, missing_integrity_material, or schema_unknown_fields.
  • Non-canonical run selectors now fail fast - runs verify --file rejects selectors outside the configured runs root and points operators to canonical selector forms.
  • OpenAI hosted preflight now blocks missing auth with actionable guidance - missing MARTIN_OPENAI_API_KEY on hosted endpoints is now a hard blocker with model/quota hints.
  • MCP scope errors now guide operators to valid alternatives - unsupported --scope local host errors now include direct user/project and Claude-local alternatives.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Keesan12/Martin-Loop

Get notified when new releases ship.

Sign up free

About Keesan12/Martin-Loop

All releases →

Related context

Earlier breaking changes

  • vmcp-v0.1.3 martin_status uses oneOf for selector exclusivity, latest as const.
  • vmcp-v0.1.3 maxIterations and maxTokens modeled as integers in tool schemas.
  • vmcp-v0.1.3 Tool schemas enforce additionalProperties: false on public contracts.
  • vmcp-v0.1.3 Packaged artifacts now require and ship server.json alongside package.json.

Beta — feedback welcome: [email protected]