This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+4 more
Summary
AI summaryRepairs broken provenance chain for the paid release without altering runtime behavior.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Binds active T3 Utility Ledger evidence to current paid release provenance. Binds active T3 Utility Ledger evidence to current paid release provenance. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Makes historical T2 activation evidence verifiable from immutable hashes independently of current provenance record. Makes historical T2 activation evidence verifiable from immutable hashes independently of current provenance record. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Commercial‑truth audit now rejects drifting T3 activation or provenance records before a release cut. Commercial‑truth audit now rejects drifting T3 activation or provenance records before a release cut. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Repairs broken provenance chain for v3.20.0‑public‑paid release. Repairs broken provenance chain for v3.20.0‑public‑paid release. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Supersedes failed v3.20.0‑public‑paid release, which had no installer assets. Supersedes failed v3.20.0‑public‑paid release, which had no installer assets. Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
ContextLattice v3.20.1: Receipts Bound to the Release
The Utility Ledger was ready. Its paid installer authorization was not: the first v3.20.0-public-paid release correctly stopped before building or publishing assets because a legacy Frontier provenance record still identified the previous release train. ContextLattice v3.20.1 repairs that proof chain without weakening the gate or changing runtime behavior.
The CLI remains the primary interface. HTTP remains the integration fallback.
What changed
- Current paid release provenance now binds the active T3 Utility Ledger evidence, exact tested source, and proof commit.
- Historical T2 activation evidence remains independently verifiable from immutable hashes instead of depending on the mutable current-release provenance record.
- The commercial-truth audit now rejects a current T3 activation or provenance record that drifts from the canonical stable tag before a release is cut.
- The failed
v3.20.0-public-paidrelease remains asset-free and is superseded byv3.20.1-public-paid.
What did not change
- Utility Ledger recording, verification, exact token accounting, analytics, advisory gates, durability, or rollback behavior.
- Public
v3.20.0, which passed its release workflow;v3.20.1carries the same runtime behavior plus the shared release-safety repair. - Agent Packet deltas, proof timelines, session lifecycle, entitlement boundaries, quickstart requirements, or third-party agent installation policy.
Verification
The repair is proof and release tooling only. Focused commercial-truth regressions verify stale current provenance is rejected while historical T2 evidence remains valid. The exact paid candidate is re-audited against the private proof root, and the paid release workflow must pass before any installer asset is published.
Rollback
Use public v3.20.1 or paid v3.20.1-public-paid. The earlier paid tag intentionally has no installer assets.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sheawinkler/ContextLattice
Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.
Related context
Related tools
Beta — feedback welcome: [email protected]