This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryRelease provenance now runs a complete evaluation contract audit for Utility Ledger releases before publishing paid artifacts.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds complete program eval-ledger audit for Utility Ledger releases. Adds complete program eval-ledger audit for Utility Ledger releases. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Correctly binds governed efficiency‑policy evaluation to Operator and Enterprise tiers. Correctly binds governed efficiency‑policy evaluation to Operator and Enterprise tiers. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Introduces `frontier_verified_efficiency_operations` identifier in policy response contract while keeping analytics as `frontier_utility_analytics`. Introduces `frontier_verified_efficiency_operations` identifier in policy response contract while keeping analytics as `frontier_utility_analytics`. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Adds detailed contract fields to release ledger including causal arms, latency, cost, etc. Adds detailed contract fields to release ledger including causal arms, latency, cost, etc. Source: llm_adapter@2026-07-18 Confidence: low |
— |
| Feature | Low |
Allows disabling `GO_UTILITY_LEDGER_ENABLED` to stop derived ledger without affecting authoritative outcomes. Allows disabling `GO_UTILITY_LEDGER_ENABLED` to stop derived ledger without affecting authoritative outcomes. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Enriches release ledger with causal arms, latency, cost, tool calls, storage bounds, failure review, rollback steps, independent review, and negative entitlement evidence as a single contract. Enriches release ledger with causal arms, latency, cost, tool calls, storage bounds, failure review, rollback steps, independent review, and negative entitlement evidence as a single contract. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Prevents commercially valid but program‑incomplete ledgers from reaching the installer workflow. Prevents commercially valid but program‑incomplete ledgers from reaching the installer workflow. Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
ContextLattice v3.20.3: Receipts Before Release
ContextLattice already refused to publish a paid artifact whose source identity drifted. v3.20.3 closes the next gap: exact source proof is necessary, but it is not enough. A release must also satisfy the complete evaluation contract behind its product claim.
The CLI remains the primary interface. HTTP remains the integration fallback.
What changed
- Release provenance now runs the complete program eval-ledger audit for Utility Ledger releases, in addition to commercial-truth validation.
- The release ledger carries exact causal arms, denominator separation, latency, cost, tool calls, bounded storage, failure review, rollback, independent review, and negative entitlement evidence as one contract.
- Starter and Team retain read-only Utility Analytics. Governed efficiency-policy evaluation is now correctly bound to Operator and Enterprise.
- The policy response contract identifies
frontier_verified_efficiency_operations; analytics remainsfrontier_utility_analytics. - Focused regressions prevent a commercially valid but program-incomplete ledger from reaching the installer workflow again.
What did not change
- The public local Utility Ledger, exact token accounting, CLI receipts, and readback behavior.
- Causal gain still requires exact matched controls; negative gains and exclusions remain visible.
- Policy evaluation remains advisory-only. It cannot silently mutate retrieval policy or ordinary memory.
- Third-party agent harnesses remain optional, and the CLI remains the prescribed product path.
Release lineage
Public v3.20.2 remains a valid release. The paid v3.20.2-public-paid tag stopped before any installer asset was built and remains asset-free. v3.20.3-public-paid is the first paid patch in this train authorized by both the exact-source and complete-evaluation gates.
Rollback
Disable GO_UTILITY_LEDGER_ENABLED to stop the derived ledger without changing authoritative Context Pack outcomes, exact token-impact rows, or session verification events. Efficiency-policy operations fail closed outside an entitled Operator or Enterprise runtime.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sheawinkler/ContextLattice
Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.
Related context
Related tools
Beta — feedback welcome: [email protected]