Skip to content

release: v0.21.9 - #181

Merged
Fail-Safe merged 31 commits into
mainfrom
next
Sep 20, 2026
Merged

Fail-Safe merged 31 commits into
mainfrom
next

Conversation

@Fail-Safe

@Fail-Safe Fail-Safe commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

When an embedding API key is configured, Noema now rejects remote cleartext HTTP endpoints before sending a request. HTTPS and loopback HTTP remain supported; unkeyed HTTP behavior is unchanged. Prepare v0.21.9 with the dependency maintenance already merged since v0.21.8.

Users with keyed remote HTTP embedding endpoints must switch to HTTPS, including endpoints on private networks. No database migration is added; the Obsidian plugin remains at v0.5.2.

Validation: make test passed (223 Rust unit tests plus integration coverage, formatting, strict Clippy, and 60 continuity benchmark tests); 121 Hermes tests passed; Obsidian tests, build, TypeScript checks, and bundle consistency passed; Homebrew metadata and repository-script tests passed.

The optimized host build and version smoke test passed. Hosted Rust/plugin CI and all CodeQL analyses passed. The release excludes unfinished local macOS service-management changes.

Fail-Safe and others added 30 commits June 11, 2026 00:00
keygen is a top-level command but was only mentioned in the federation
event-signing prose; add it to the command table next to the federation
block so it's discoverable when scanning the command list.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
chore: reconcile next with released history
…orrectness

feat: preserve federation state and add dynamic listeners
* feat: add experimental Rust rewrite and comparison suite

* fix: fail closed for unsupported Rust HTTP security

* feat: validate persistent MCP and signed federation replay

* feat: add mixed Rust federation experiments

* feat(rust): add background federation experiments

* feat(rust): add authenticated TLS federation

* feat(rust): add consolidation election foundation

* feat(rust): add consolidation pass coordination

* feat(rust): add heuristic promotion pass

* feat(rust): add consolidation cadence and graduation

* feat(rust): add model-driven consolidation

* feat(rust): add consolidate CLI parity

* test(rust): compare real-model consolidation

* feat(rust): add watcher parity

* feat(rust): add semantic search parity

* feat(rust): tighten MCP contract parity

* feat(rust): add plugin lifecycle parity

* feat(rust): complete advanced MCP parity

* feat(rust): add functional TUI parity

* feat(rust): add TLS certificate lifecycle parity

* feat(rust): reconcile live federation workers

* test(rust): add lock and I/O fault gates

* fix(rust): roll back failed trace transactions

* fix(rust): recover interrupted trace mutations

* fix(rust): recover interrupted trace deletion

* fix(recovery): guard mixed-runtime takeover

* feat(rust): add safe cortex restore

* feat(rust): expose safe recovery status

* feat(rust): recover interrupted cortex restore

* fix(rust): persist configuration atomically

* test(rust): validate live TUI lifecycle

* feat(rust): complete recovery and verification parity

* feat(rust): complete migration and operational parity

* test(rust): add blinded qualitative comparison

* fix(consolidation): align model quality across runtimes

* fix(tui): match Go visual hierarchy

* feat(rust): qualify standard profile at scale

* test(rust): qualify APFS storage recovery

* docs: clarify Rust workload comparison

* docs: align Rust report charts

* feat: make Rust the production implementation

* docs: remove unreleased durability terminology

* docs: add Rust source-size comparison

* docs: refine source-size comparison

* fix(backup): preserve Obsidian trash alias compatibility

* fix(http): separate listener and Host allowlists

* docs: record Rust deployment qualification

* fix(ci): satisfy Rust 1.88 clippy
* fix(release): authenticate Homebrew tap pushes (#143)

* docs: separate public Rust rationale from maintenance (#144)

* feat(tags): add cortex-wide tag management
Reconcile next with the released v0.21.7 source tree and apply the validated v0.21.8 retrieval and compatibility patch. Rust, plugin, repository, and optimized-build checks pass.
* release: v0.20.0 — Rust implementation

Replace the Go runtime with the qualified Rust implementation, preserve established storage and protocol contracts, and retain the migration evidence. Includes final watcher and Obsidian Streamable HTTP fixes.

* fix(release): authenticate Homebrew tap pushes (#143)

* docs: separate public Rust rationale from maintenance (#144)

* release: v0.21.0 — tag management (#146)

* feat(tags): add cortex-wide tag management

* release: v0.21.0 — tag management

* fix(release): eliminate Windows build warning (#147)

* fix(mcp): emit portable schema version metadata (#148)

* fix(federation): ignore retired clock keys during causal replay (#149)

* release: v0.21.3 — integrations and service durability (#150)

* fix(integrate): preserve Rust 1.88 compatibility

* fix(integrate): satisfy Rust 1.88 linting

* feat(integrate): add managed agent client integrations

* fix(http): harden local service connectivity

* release: v0.21.3 — integrations and service durability

* release: v0.21.4 — safe sync reconciliation

Add actionable invalid-file sync diagnostics, event-backed long-tier reconciliation, legacy reference normalization, accurate sync accounting, safe recovery behavior, private reconciliation artifacts, and focused regression coverage.

* fix(watch): preserve clipped frontmatter fields (#152)

Parse onboarding metadata independently so one incompatible field cannot erase valid neighbors. Preserve non-conflicting properties and accept scalar or list forms for authors and tags.

* feat(obsidian): show trace tiers in file explorer (#153)

* release: v0.21.6 (#154)

* Release/v0.21.6 (#155)

* release: v0.21.6

* feat(memory): add safe Obsidian tag normalization

* feat(memory): add bounded cross-agent continuity (#156)

Add bounded continuity retrieval and capture sessions, benchmark regression coverage, and qualified cross-harness evaluation documentation.

* fix(obsidian): preserve trace identity during title edits (#157)

Add semantic title editing and canonical filename restoration. Prepare v0.21.7 with Obsidian plugin v0.5.2.

* release: v0.21.8

Add opt-in bounded Hermes retrieval and fix MCP metadata, legacy event recovery, and managed JSONC formatting. Full local validation and hosted Rust/plugin checks passed.

* Create dependabot.yml
* Next (#161)

* docs: list `noema keygen` in the command reference table

keygen is a top-level command but was only mentioned in the federation
event-signing prose; add it to the command table next to the federation
block so it's discoverable when scanning the command list.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(federation): allow same-name pinned peer events

* feat(obsidian): add Noema-backed trace search

* fix(federation): normalize vector clocks and tighten promotion scoring (#130)

* fix(federation): preserve tier state across reordered events

* feat(serve): add conditional dynamic listeners

* fix(db): apply migrations atomically

* chore: correct brand asset path resolution

* test(hermes): run integration coverage in CI

* test(hermes): isolate provider binary discovery

* feat(plugin): add embedded install and drift checks

* fix(release): limit Hermes plugin archive contents

* chore: normalize example identifiers in fixtures

* feat: replace Noema with the Rust implementation (#139)

* feat: add experimental Rust rewrite and comparison suite

* fix: fail closed for unsupported Rust HTTP security

* feat: validate persistent MCP and signed federation replay

* feat: add mixed Rust federation experiments

* feat(rust): add background federation experiments

* feat(rust): add authenticated TLS federation

* feat(rust): add consolidation election foundation

* feat(rust): add consolidation pass coordination

* feat(rust): add heuristic promotion pass

* feat(rust): add consolidation cadence and graduation

* feat(rust): add model-driven consolidation

* feat(rust): add consolidate CLI parity

* test(rust): compare real-model consolidation

* feat(rust): add watcher parity

* feat(rust): add semantic search parity

* feat(rust): tighten MCP contract parity

* feat(rust): add plugin lifecycle parity

* feat(rust): complete advanced MCP parity

* feat(rust): add functional TUI parity

* feat(rust): add TLS certificate lifecycle parity

* feat(rust): reconcile live federation workers

* test(rust): add lock and I/O fault gates

* fix(rust): roll back failed trace transactions

* fix(rust): recover interrupted trace mutations

* fix(rust): recover interrupted trace deletion

* fix(recovery): guard mixed-runtime takeover

* feat(rust): add safe cortex restore

* feat(rust): expose safe recovery status

* feat(rust): recover interrupted cortex restore

* fix(rust): persist configuration atomically

* test(rust): validate live TUI lifecycle

* feat(rust): complete recovery and verification parity

* feat(rust): complete migration and operational parity

* test(rust): add blinded qualitative comparison

* fix(consolidation): align model quality across runtimes

* fix(tui): match Go visual hierarchy

* feat(rust): qualify standard profile at scale

* test(rust): qualify APFS storage recovery

* docs: clarify Rust workload comparison

* docs: align Rust report charts

* feat: make Rust the production implementation

* docs: remove unreleased durability terminology

* docs: add Rust source-size comparison

* docs: refine source-size comparison

* fix(backup): preserve Obsidian trash alias compatibility

* fix(http): separate listener and Host allowlists

* docs: record Rust deployment qualification

* fix(ci): satisfy Rust 1.88 clippy

* docs: prepare README for Rust release (#140)

* fix(obsidian): support Streamable HTTP responses

* chore: remove Go runtime remnants (#141)

* fix(watch): ignore non-mutating filesystem events

* feat(tags): add cortex-wide tag management (#145)

* fix(release): authenticate Homebrew tap pushes (#143)

* docs: separate public Rust rationale from maintenance (#144)

* feat(tags): add cortex-wide tag management

* chore: reconcile next and prepare v0.21.8

Reconcile next with the released v0.21.7 source tree and apply the validated v0.21.8 retrieval and compatibility patch. Rust, plugin, repository, and optimized-build checks pass.

* Create dependabot.yml (#160)

* release: v0.20.0 — Rust implementation

Replace the Go runtime with the qualified Rust implementation, preserve established storage and protocol contracts, and retain the migration evidence. Includes final watcher and Obsidian Streamable HTTP fixes.

* fix(release): authenticate Homebrew tap pushes (#143)

* docs: separate public Rust rationale from maintenance (#144)

* release: v0.21.0 — tag management (#146)

* feat(tags): add cortex-wide tag management

* release: v0.21.0 — tag management

* fix(release): eliminate Windows build warning (#147)

* fix(mcp): emit portable schema version metadata (#148)

* fix(federation): ignore retired clock keys during causal replay (#149)

* release: v0.21.3 — integrations and service durability (#150)

* fix(integrate): preserve Rust 1.88 compatibility

* fix(integrate): satisfy Rust 1.88 linting

* feat(integrate): add managed agent client integrations

* fix(http): harden local service connectivity

* release: v0.21.3 — integrations and service durability

* release: v0.21.4 — safe sync reconciliation

Add actionable invalid-file sync diagnostics, event-backed long-tier reconciliation, legacy reference normalization, accurate sync accounting, safe recovery behavior, private reconciliation artifacts, and focused regression coverage.

* fix(watch): preserve clipped frontmatter fields (#152)

Parse onboarding metadata independently so one incompatible field cannot erase valid neighbors. Preserve non-conflicting properties and accept scalar or list forms for authors and tags.

* feat(obsidian): show trace tiers in file explorer (#153)

* release: v0.21.6 (#154)

* Release/v0.21.6 (#155)

* release: v0.21.6

* feat(memory): add safe Obsidian tag normalization

* feat(memory): add bounded cross-agent continuity (#156)

Add bounded continuity retrieval and capture sessions, benchmark regression coverage, and qualified cross-harness evaluation documentation.

* fix(obsidian): preserve trace identity during title edits (#157)

Add semantic title editing and canonical filename restoration. Prepare v0.21.7 with Obsidian plugin v0.5.2.

* release: v0.21.8

Add opt-in bounded Hermes retrieval and fix MCP metadata, legacy event recovery, and managed JSONC formatting. Full local validation and hosted Rust/plugin checks passed.

* Create dependabot.yml

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* build(deps): bump clap_complete from 4.6.9 to 4.6.11 (#169)

Bumps [clap_complete](https://github.com/clap-rs/clap) from 4.6.9 to 4.6.11.
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.9...clap_complete-v4.6.11)

---
updated-dependencies:
- dependency-name: clap_complete
  dependency-version: 4.6.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump reqwest from 0.13.4 to 0.13.5 (#174)

Bumps [reqwest](https://github.com/seanmonstar/reqwest) from 0.13.4 to 0.13.5.
- [Release notes](https://github.com/seanmonstar/reqwest/releases)
- [Changelog](https://github.com/seanmonstar/reqwest/blob/master/CHANGELOG.md)
- [Commits](seanmonstar/reqwest@v0.13.4...v0.13.5)

---
updated-dependencies:
- dependency-name: reqwest
  dependency-version: 0.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump actions/setup-node from 4 to 7 (#162)

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump esbuild from 0.21.5 to 0.28.2 in /plugins/obsidian (#172)

Bumps [esbuild](https://github.com/evanw/esbuild) from 0.21.5 to 0.28.2.
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2024.md)
- [Commits](evanw/esbuild@v0.21.5...v0.28.2)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump ed25519-dalek from 2.2.0 to 3.0.0 (#165)

Bumps [ed25519-dalek](https://github.com/dalek-cryptography/curve25519-dalek) from 2.2.0 to 3.0.0.
- [Release notes](https://github.com/dalek-cryptography/curve25519-dalek/releases)
- [Changelog](https://github.com/dalek-cryptography/curve25519-dalek/blob/3.0.0/CHANGELOG.md)
- [Commits](dalek-cryptography/curve25519-dalek@ed25519-2.2.0...3.0.0)

---
updated-dependencies:
- dependency-name: ed25519-dalek
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump builtin-modules in /plugins/obsidian (#175)

Bumps [builtin-modules](https://github.com/sindresorhus/builtin-modules) from 3.3.0 to 5.3.0.
- [Release notes](https://github.com/sindresorhus/builtin-modules/releases)
- [Commits](sindresorhus/builtin-modules@v3.3.0...v5.3.0)

---
updated-dependencies:
- dependency-name: builtin-modules
  dependency-version: 5.3.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps-dev): bump @types/node in /plugins/obsidian (#166)

Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 20.19.39 to 26.6.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump actions/download-artifact from 4 to 8 (#164)

Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v8)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump actions/upload-artifact from 4 to 7 (#167)

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump actions/checkout from 6 to 7 (#170)

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump actions/cache from 4 to 6 (#173)

Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Require https or loopback http when an embedding API key is present so
bearer tokens are not sent to remote http endpoints.
Prepare the embedding API-key transport protection and dependency maintenance patch release.
@Fail-Safe
Fail-Safe merged commit 84f026d into main Sep 20, 2026
9 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant