This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Moderate signalThe trust-layer now includes deterministic tamper detection and a quote‑fidelity gate for hardened security.
Why it matters: Hardens the trust‑layer with deterministic tamper detection; severity score 90 signals critical importance for SREs and security engineers monitoring integrity guarantees.
Summary
AI summaryUpdates Changes since v1.9.0, evals, and trust across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Hardens trust-layer with deterministic tamper detection and quote-fidelity gate. Hardens trust-layer with deterministic tamper detection and quote-fidelity gate. Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Feature | Medium |
HR specialist surfaces each workforce risk as a distinct finding. HR specialist surfaces each workforce risk as a distinct finding. Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Dependency | Low |
Update Homebrew formula to version 1.9.0. Update Homebrew formula to version 1.9.0. Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Performance | Low |
Increase eval F1 no‑regression tolerance from 0.05 to 0.15. Increase eval F1 no‑regression tolerance from 0.05 to 0.15. Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Bugfix | Medium |
Treat agent timeout/non-success as INCONCLUSIVE instead of 0.0 recall. Treat agent timeout/non-success as INCONCLUSIVE instead of 0.0 recall. Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Bugfix | Medium |
Close three masking holes discovered by competitive audit of fa66531. Close three masking holes discovered by competitive audit of fa66531. Source: llm_adapter@2026-06-05 Confidence: high |
— |
Full changelog
Changes since v1.9.0
- v1.10.0: trust-layer hardening + eval-robustness overhaul
- test(evals): size F1 no-regression tolerance to real variance (0.05 -> 0.15)
- test(evals): authoritative median-of-3 baseline — all 9 specialists pass live
- test(evals): treat agent timeout/non-success as INCONCLUSIVE, not 0.0 recall
- feat(agents): HR specialist surfaces each workforce risk as a distinct finding
- test(evals): capacity-K (K=2) recall matching — credit consolidation, cap stuffing
- test(evals): close 3 masking holes found by competitive audit of fa66531
- test(evals): make agent evals reliable and cover all 9 specialists (no masking)
- test(trust): cover engine wiring for tamper injection + numerical-audit text_dir
- docs(devto): update trust-layer article for shipped deterministic gates
- feat(trust): wire deterministic tamper detection + add quote-fidelity gate
- content: add dev.to article on the trust layer (audited + verified)
- brand: add iris logo — README header + MkDocs theme logo/favicon
- docs: add "How the Agents Work" — an audit-first agent anatomy tour
- Update Homebrew formula to 1.9.0
Install
pip install dd-agents==1.10.0
Docker
docker pull zoharbabin/due-diligence-agents:1.10.0
Full Changelog: https://github.com/zoharbabin/due-diligence-agents/compare/v1.9.0...v1.10.0
Security Fixes
- test(trust): cover engine wiring for tamper injection + numerical-audit text_dir
- test(evals): close 3 masking holes found by competitive audit of fa66531
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Due Diligence Agents
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]