This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+4 more
Summary
AI summaryInstaller guard no longer misclassifies disabled Frontier T1 compatibility schema as paid implementation.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Installer guard no longer misclassifies disabled Frontier T1 compatibility schema as paid implementation. Installer guard no longer misclassifies disabled Frontier T1 compatibility schema as paid implementation. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
Full changelog
ContextLattice v4.0.1: Fail Closed. Not False Closed.
ContextLattice v4.0.0 shipped the complete Aggregate Signal runtime and passed its exact-tree, privacy, and source-provenance gates. Its installer workflow then stopped before compilation because the public packaging classifier mistook a disabled compatibility status envelope for paid runtime code.
v4.0.1 repairs that classifier without weakening the product boundary or changing runtime behavior. The CLI remains the primary interface. HTTP remains the integration fallback.
What Changed
- The public installer guard no longer classifies the disabled Frontier T1 compatibility schema as a paid implementation.
- Every actual T2 and T4-T10 paid governance marker remains forbidden in public runtime source.
- A focused regression test locks this distinction into the public release workflow.
What Did Not Change
- Aggregate Signal preview, queueing, reporting, accounting, consent, replay, expiry, revocation, or opt-out behavior.
- The exclusion of raw memory, prompts, embeddings, paths, project names, exact timestamps, secrets, and stable installation identifiers.
- Paid and private source boundaries, entitlement rules, or the six-review production activation hold.
Release Lineage
The immutable v4.0.0 tag remains the reviewed Frontier 30 completion tree and intentionally has no installer assets. v4.0.1 carries the same runtime behavior plus the packaging repair and is the first installer-complete public v4 release.
Verification
The patch is accepted only if the exact public runtime-marker scan passes, the focused release-workflow regression remains green, a clean tagged Linux installer builds locally, and the hosted macOS, Linux, and Windows jobs publish exactly three assets.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sheawinkler/ContextLattice
Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.
Related context
Related tools
Beta — feedback welcome: [email protected]