AEGISCONTROL

Changelog

Format: Keep a Changelog. Versioning: semantic, with the caveat that nothing here is a production release. Until an external assessor signs off, every version is a demonstrator.

An entry is added for anything that changes a trust boundary, a signed artefact, a failure mode or a reproduction command. Refactors that change none of those belong in the git history, not here.

[0.15.0] — 2026-09-07

Another program's evidence, anchored here. AEGIS gains one route and one artefact type so that MAIVAR — a read-only Windows posture scanner kept in a separate repository on purpose — can deposit the Merkle root of each relevé in the transparency log. What crosses the boundary is a digest and four small fields; the attestation is exactly as narrow. Nothing in the kernel changed, and the demo's captured values are still those of the 0.14.1 run.

Added

Noted

[0.14.2] — 2026-09-02

The public site, as a product surface. Nothing in the kernel changed: the demo's captured values are still those of the 0.14.1 run, and the demo page says so. Until the DNS record for the Byss subdomain exists, the site is served from a Vercel alias, and its canonical links say where it actually lives.

Added

Changed

[0.14.1] — 2026-09-02

The console catches up with 0.14.0. The kernel had gained a second action, a standard receipt format and a queryable log; the console hard-coded pod quarantine and called nine routes, all older than any of that.

Fixed

Added

Changed

[0.14.0] — 2026-09-02

The release where AEGIS stops being one action, one format and one log nobody can ask. Thirty-two commits since 0.13.1; what follows is the part that changes a trust boundary, a signed artefact, a failure mode or a reproduction command. The rest is in the git history.

Two disciplines ran through all of it and are worth naming once. Every new test was mutation-tested — the guard it protects was removed and the test had to fall, and several did not on first writing. And every hand-written encoder is read back by something that is not AEGIS.

Security

Added

Changed

Fixed

Not claimed

Reproduce: npm run verify, npm run adversary, bash scripts/verifier-check.sh, npm run formal:verify.

[0.13.1] — 2026-09-01

Dependency updates, and the two defects they exposed. Nothing here changes a trust boundary; two things restore a gate that had stopped guarding anything.

Fixed

Added

Changed

[0.13.0] — 2026-09-01

Security

Added

Changed

Added, after the report

Known gaps

Unchanged and still true: no independent audit, no production credentials, one cluster/CNI combination, local key custody. See docs/threat-model.md and docs/production-roadmap.md, which are the authoritative statements of what is not proven.

[0.12.0] — 2026-08-29

Imported as the repository's first commit. Signed missions, evidence provenance, one-shot capabilities, ExecutionProof, signed receipts, PostgreSQL authority, Temporal restoration, OpenBao Transit signing, the typed mTLS executor, the proof admission webhook, the independent observer and the S3 Object Lock sink.