What’s New

ruflo v3.34.0

v3.34.0

v3.34.0 — AGNTCY/Outshift runtime integration

Added 6
  • Add new CLI verbs `ruflo transport use slim`, `ruflo agent publish`, and `ruflo swarm join <namespace>` that exit with code 0 and a clear message when RUFLO_AGNTCY_SLIM_ENDPOINT is unset
  • Add CASA (Continuous Agentic Semantic Authorization) deterministic compiler with deny-by-default enforcement gate and Ed25519-signed decision receipts to .swarm/casa-receipts.jsonl
  • Add AGNTCY OTel span attributes for coordination.episode and authorization.decision
  • Add companion Rust crate v3/crates/ruflo-agntcy mirroring TypeScript enforcement logic with LocalTransport and SlimTransport stub behind non-default slim Cargo feature
  • Publish companion package @metaharness/agntcy for build-time identity, OASF export, Directory publish, and semantic observability
  • Add npm Trusted Publishing release workflow with immutable tag-pinned checkout, full test/build/pack/install smoke-test gate, published-package integrity verification, and dist-tag rollout
Fixed 2
  • Pin @agntcy/slim-bindings to confirmed-working alpha 2.0.0-alpha.5 with verified live end-to-end compatibility
  • Fix security scan command to fail closed on unvalidated --depth, --type, and --target parameters instead of failing open
Removed 1
  • Remove silent success behavior from security scan --type container, now rejected instead
Deprecated 1
  • Deprecate security scan --depth full in favor of deep with a warning
AGNTCY/Outshift runtime integration (ADR-378/379/380)

Optional, removable augmentation per ADR-150's pattern — the kernel stays fully operational with these packages absent.

  • New CLI verbs: ruflo transport use slim, ruflo agent publish, ruflo swarm join <namespace>. All exit 0 with a clear message when RUFLO_AGNTCY_SLIM_ENDPOINT is unset — no fake success paths.
  • CASA (Continuous Agentic Semantic Authorization) — deterministic free-text-objective → bounded allow/deny/budget/expiry envelope compiler, deny-by-default enforcement gate, Ed25519-signed decision receipts (.swarm/casa-receipts.jsonl).
  • AGNTCY OTel span attributescoordination.episode, authorization.decision.
  • Companion Rust crate v3/crates/ruflo-agntcy mirrors the TS enforcement logic (real in-process LocalTransport, SlimTransport stub behind a non-default slim Cargo feature).
  • Companion package @metaharness/agntcy (build-time half — identity, OASF export, Directory publish, semantic observability) published for the first time from the sibling metaharness repo.
  • See it in action: AGNTCY showcase — a real trace and the presentation deck.
npm Trusted Publishing release workflow (ADR-378)

.github/workflows/stable-npm-release.yml publishes the three-package stable train (@claude-flow/cli, claude-flow, ruflo) from an immutable, tag-pinned checkout with a full test/build/pack/install smoke-test gate before any registry write, verifies published-package integrity against the locally-built archive, and rolls out latest/alpha/v3alpha dist-tags together. This release is the first real run of that workflow.

Fixed
  • @agntcy/slim-bindings pinned to the confirmed-working alpha (2.0.0-alpha.5) — the SLIM maintainers moved off uniffi-bindgen-react-native (incompatible with plain Node) onto @ubjs/core/@ubjs/node; verified live end-to-end.
  • security scan failed open on unvalidated --depth/--type/--target — all three now fail closed before anything is scanned or written.
Changed / Removed
  • security scan --depth full deprecated (normalises to deep with a warning).
  • security scan --type container now rejected instead of silently reporting clean (breaking for pipelines passing --type container).

Full changelog: CHANGELOG.md


Install: npx ruflo@latest doctor · npx ruflo@latest agent publish --help

View original

Discussion