Skip to content

This release adds 3 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agent-framework agent-orchestration ai-infra ai-interface context-engineering context-management
+4 more
go long-horizon-agents long-horizon-intelligence rust

Summary

AI summary

Updates What Shipped, ContextLattice v4.0.0, and /aggregate-signal.md across a mixed release.

Changes in this release

Feature Low

Adds `contextlattice_aggregate_signal` CLI command suite.

Adds `contextlattice_aggregate_signal` CLI command suite.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Introduces five versioned contracts for contribution, report, accounting, governance, and research boundaries.

Introduces five versioned contracts for contribution, report, accounting, governance, and research boundaries.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Implements strict allowlist of clipped numerical and categorical sufficient statistics.

Implements strict allowlist of clipped numerical and categorical sufficient statistics.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Enforces recursive rejection of raw text, memory, prompts, embeddings, paths, project names, timestamps, secrets, and installation identifiers.

Enforces recursive rejection of raw text, memory, prompts, embeddings, paths, project names, timestamps, secrets, and installation identifiers.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Limits contributions to one per installation commitment, metric, and week.

Limits contributions to one per installation commitment, metric, and week.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Applies cohort suppression for cohorts smaller than 20 participants.

Applies cohort suppression for cohorts smaller than 20 participants.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Sets per‑release epsilon ≤ 0.25, rolling 90‑day epsilon ≤ 2.0, and delta ≤ 0.000001.

Sets per‑release epsilon ≤ 0.25, rolling 90‑day epsilon ≤ 2.0, and delta ≤ 0.000001.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Caps owner‑only atomic ledgers at 64 MiB and 100,000 records.

Caps owner‑only atomic ledgers at 64 MiB and 100,000 records.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Provides idempotent reports with differencing rejection, expiry, revocation, and hash‑linked audit receipts.

Provides idempotent reports with differencing rejection, expiry, revocation, and hash‑linked audit receipts.

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Low

Adds aggregate‑ready quality, policy, and Context Mesh source statistics without altering retrieval or memory‑write behavior.

Adds aggregate‑ready quality, policy, and Context Mesh source statistics without altering retrieval or memory‑write behavior.

Source: llm_adapter@2026-07-20

Confidence: medium

Full changelog

ContextLattice v4.0.0

Memory That Compounds Without Giving Itself Away

ContextLattice v4 closes the Frontier 30 program with Aggregate Signal: a bounded path for learning from system outcomes without exporting the memories, prompts, projects, paths, or identities that produced them.

The CLI remains the primary interface. Preview is local and non-persistent. Queueing requires explicit opt-in. Cohorts smaller than 20 disappear behind suppression. Privacy composition is bounded. Replays cannot become differencing probes. Opt-out deletes unreleased work and never pretends an already released aggregate can be recalled.

What Shipped

  • contextlattice_aggregate_signal and contextlattice aggregate-signal for preview, queue, report, status, opt-out, and entitled governance.
  • Five versioned contracts for contribution, report, accounting, paid governance, and secure-aggregation research boundaries.
  • A strict allowlist of clipped numerical and categorical sufficient statistics.
  • Recursive rejection of raw text, memory, prompts, embeddings, paths, project names, exact timestamps, secrets, and stable installation identifiers.
  • One contribution per installation commitment, metric, and week.
  • Cohort suppression below 20, per-release epsilon at most 0.25, rolling 90-day epsilon at most 2.0, and delta at most 0.000001.
  • Owner-only atomic ledgers capped at 64 MiB and 100,000 records.
  • Idempotent reports, changed-parameter differencing rejection, expiry, revocation, and hash-linked paid audit receipts.
  • Aggregate-ready quality, policy, and Context Mesh source statistics without changing retrieval or memory-write behavior.
  • Closed-world public, paid, and development projections that mechanically reject paid or research implementation leakage into the wrong artifact.

Commercial Boundary

The public runtime ships the local Aggregate Signal core. Operator and Enterprise artifacts add credential-derived workspace isolation and governance. Production paid contribute and report remain hard-blocked until six independent privacy and utility reviews pass.

This is a controlled preview, not a formal privacy certification. The release ships enforceable minimization, suppression, accounting, replay, retention, and consent controls while refusing to market pending evidence as finished proof.

Why v4

The Frontier train changed the category of the product. ContextLattice no longer only remembers. It proves continuity, measures context utility, explains retrieval, learns policy under gates, adapts briefs to agents, moves work without dissolving trust, evolves verified skills, removes cold starts, and can now learn aggregate system signal without surrendering raw memory.

See docs/aggregate-signal.md for the operating contract.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track sheawinkler/ContextLattice

Get notified when new releases ship.

Sign up free

About sheawinkler/ContextLattice

Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.

All releases →

Related context

Earlier breaking changes

  • v3.17.3 Agent guidance now mandates the `/agents/tasks` route family.
  • v3.17.3 Task worker now checks approval before any execution steps.

Beta — feedback welcome: [email protected]