Skip to content

Releases: AetherAI3/aether-agent

v0.4.0

Choose a tag to compare

@AetherAI3 AetherAI3 released this 06 Oct 12:16
3cf3f72

v0.4.0 repairs terminal stream recovery, interactive authentication recovery and filesystem protocol v4 guarded reads. It also fixes Windows credential-reader contention during atomic token replacement and resolves Windows short workspace paths to their native real path for ownership checks.

Release source: 3cf3f7255e582374426c810311149c5e8b8cebb6, tree cfc0b2cc4299ba782fb219e82b42955f515097d4. PR #291 also makes package permissions consistent across the Linux builders. Its qualified tree is preserved in merged main, and the clean main rebuild matches the approved package byte for byte.

Package SHA-256: a3550c7de43109c12b27fc3dbd5d3933091b58e87ed87cc454e6491305823229.

All 78 scoped packaging/release tests and 20 manual gates passed. Pinned private ATS parity passed 110 Node tests and 16 Python tests with no skips. Seven merged-main checks passed, including fresh locked installation, production policy, dependency audit, SBOM and exact package digest. The qualification summary states each runner's actual scope; earlier platform suites and their skips remain separate evidence.

aether-agents@0.4.0 is published on npm as latest. Registry metadata and the downloaded tarball match the approved package digest. This was a direct maintainer publication without npm provenance under the owner's one-time release exception. The owner approved a one-time direct maintainer publication without npm provenance, substituting sealed exact-source manual receipts for the blocked native release run, required Actions artifact upload and native private ATS gate. GitHub rules, future hosted/provenance workflows and npm security settings remain unchanged. No native GitHub green checks or signed native installers are claimed. Provider-gated skipped tests and existing holds remain explicit.

Guarded Linux reads up to 16 MiB hash a bounded buffer and return ranges from those same bytes; same-size rewrites are rejected even with unchanged timestamps. Guarded reads above 16 MiB or on other platforms return revision_unsupported before content I/O. Larger files retain unguarded bounded paging and existing containment, symlink, UTF-8, conflict and output checks.

The current package, SBOM and merged-source packet are covered by SHA256SUMS. Earlier candidate assets are preserved with historical names and unchanged bytes; historical-asset-map.json records their original names and digests. PyPI publication is separate.

Aether Agent v0.3.2 — one line again

Choose a tag to compare

@AetherAI3 AetherAI3 released this 03 Sep 19:11
6864d71

This patch reunites the v0.3.1 maintenance line with main.

  • The v0.3.1 fixes are on main. v0.3.1 was released from a branch that was never merged, so main moved forward without its browser-launcher verification and browser-login recovery path — while still declaring 0.3.0, a version older than the one on the registry. That line is merged, and the declared version leads the published one again.
  • Browser sign-in reports what actually happened. Opening the sign-in page now waits for the operating system launcher to start or fail, so a machine with no browser says so instead of reporting a launch it only attempted.
  • No new surface. This patch adds no command, flag, or contract of its own. The device-runtime, telemetry, and session-library work already on main is carried by the merge and is not announced as new here.

Evidence: operator packet · release record

Aether Agent v0.3.1 — first-run recovery

Choose a tag to compare

@AetherAI3 AetherAI3 released this 29 Aug 11:10

This compatibility patch improves first-run recovery without pulling in the later device-runtime work from main.

  • Stops before executing on an unsupported Node.js runtime and prints the upgrade path.
  • Continues browser-based sign-in with the displayed URL and code when the system browser cannot open.
  • Publishes from the protected release/0.3 head after Ubuntu, Windows, supply-chain, and release-truth checks passed.

Aether Agent v0.3.0

Choose a tag to compare

@AetherAI3 AetherAI3 released this 28 Aug 12:34
fb7ceb9

Aether Agent 3.0

Aether Agent 3.0 turns local coding work into a durable, verifiable workflow
that can move between sessions, models, checkouts, and machines without handing
away tool authority.

What changed

  • Durable work and handoffs. Resume project sessions, inspect their real
    continuity state, and export bounded continuation records without absolute
    paths, file contents, shell history, or credentials.
  • Review to pull request. aether review binds verification to the current
    commit and working tree; aether ship publishes only the reviewed head after
    explicit action approval.
  • Skills and capabilities. Six built-in skills ship in the package. Skills
    and AGENTS.md now participate in real runs, and skill policy can only narrow
    the available tool surface.
  • Headless execution. aether exec provides versioned JSONL protocols,
    repository-bound checkpoints, acknowledged controls, confined agent
    definitions, receipts, and host-authoritative verification.
  • Local Ollama workflow. Setup, diagnosis, model listing, selection, and
    pulls are explicit, namespaced, and consent-gated. A plain npm install can run
    the packaged local brain.
  • Managed previews. Preview start, readiness, open, logs, status, and stop
    are owned by a loopback-only supervisor with one-use local control and full
    process-tree cleanup.
  • Generated public truth. The command manifest, command reference, model
    catalogue, package inventory, and release claims are checked together.

Security and release hardening

  • Local tools remain path-confined and permission-gated.
  • Credentials, absolute paths, private memory, and file contents are excluded
    from portable handoffs and support bundles.
  • Cancellation and preview stop clean up full process trees without attaching
    to stale or unrelated PIDs.
  • CI qualifies Linux, Windows, the packed supply chain, and CodeQL on the exact
    release head.
  • The npm workflow rebuilds from the tag, produces a CycloneDX SBOM, attests the
    package, and publishes with provenance through the owner-gated environment.

Install

Requires Node.js 24 or newer.

npm install -g aether-agents@0.3.0 --ignore-scripts
aether --version

Known limitations

  • Production Agent DevSessions are currently disabled. Hosted coding and the
    Cloud aether exec driver fail closed instead of degrading into server-side
    chat execution. Local Ollama and model-free self-test paths are available.
  • The Aether Online/Code redemption contract is not exposed as a supported
    Agent command in this release.
  • /rc remote viewing is not part of v0.3.0; its viewer and device-enrollment
    dependencies remain follow-up work.

Full verification and rollback evidence is recorded in the
v0.3.0 operator packet.