This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+4 more
Summary
AI summaryRemoved an unused machine-binding test path from the public gateway fixture.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Added a regression check that rejects paid machine‑binding vocabulary in gateway source. Added a regression check that rejects paid machine‑binding vocabulary in gateway source. Source: llm_adapter@2026-07-14 Confidence: low |
— |
| Bugfix | Low |
Removed an unused machine-binding test path from the public gateway fixture. Removed an unused machine-binding test path from the public gateway fixture. Source: llm_adapter@2026-07-14 Confidence: high |
— |
Full changelog
ContextLattice v3.17.4 - Trust, Delivered
The v3.17.3 runtime hardening landed cleanly, and its public installer boundary caught one dead paid-lane environment key in a test fixture before artifacts were published. This forward-only patch removes that residue, locks the boundary with a regression assertion, and sends the exact public tree through the complete installer pipeline.
What changed
- Removed an unused machine-binding test path from the public gateway fixture.
- Added a public-lane regression check that rejects paid machine-binding vocabulary in gateway source.
- Preserved every v3.17.3 runtime hardening contract unchanged.
- Advanced all product lanes together so version, documentation, installers, and commercial truth stay coherent.
What did not change
- No runtime feature or API behavior changed from v3.17.3.
- The CLI remains the primary interaction path.
- Public and paid feature boundaries remain intact.
- No third-party harness is installed automatically.
- No new daemon, scheduler, or Python live-runtime dependency was added.
- Public artifacts contain no private planning material or machine-local paths.
Verification
The release gate covers the public payload source-integrity scan, commercial-truth generation and audits, Go tests, Pi/Droid task-worker tests, public synchronization and leak guards, exact tag provenance, and complete macOS, Linux, and Windows artifact workflows.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sheawinkler/ContextLattice
Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.
Related context
Related tools
Beta — feedback welcome: [email protected]