Changelog

What changed in the governance contract, and what it means for anyone reading or writing these artefacts.

The compatibility promise is in README.md and enforced by check-additive.mjs: within a major version, changes are additive only. A new optional field or a new member of an open vocabulary is a minor or patch change. Renaming, removing, narrowing or redefining a field requires a major version and a documented migration. An entry below that would break a consumer is, by that rule, a major version — so if you are on 1.x, nothing below this line can break you.

The format is Keep a Changelog, and this project uses semantic versioning over the schema set, not over the tooling in this repository.

Unreleased

Added

Changed

Fixed

Security

1.2.1 — 2026-10-06

Tooling only; the SPEC's schema set stays 1.2 (no normative change) and /1.x/ served the 1.2.1 schemas when it was tagged, additive over 1.2.0 by one field (/1.x/ serves the schemas on main, which may carry description-only changes ahead of the next tag; /1.2.1/ is the frozen copy); schemaSetVersion and index.json's schema_set follow the package version, of which only the major is load-bearing. Found by pinning the reference implementation to 1.2.0: the type generator, the Pages deploy on a tag, and the narrowing vectors being the reference's own bytes. One additive field, capabilities.tool_args on the plugin schemas, so capabilities stays the lease allow shape property for property.

Fixed

1.2.0 — 2026-10-05

Schema set 1.2 (CDF spec contract-batch-two-implement-all, DR-183): the second review's fourteen improvements, from a package that could not run its own test to a corpus that runs under six validators, Ajv among them. Additive within 1.x by the contract's own rule, mechanically checked: against 1.1.0 the guard reports 115 allow-listed tightenings, covered by 58 of the allow-list's 110 entries (an entry at a definition's path covers every property in its schema that refers to it; the other 52 entries are 1.1.0's), each naming the exact value it admits and the fixture or recorded check that proves no conformant writer ever produced what it now refuses, and every real journal in the reference deployment validates with zero rejections (33,608 audit records, 19,231 CDI signals, 995 provenance front-matter blocks, 2 assessments, the six-line lease journal, the workspace config). No byte of any existing hash or signature changes. One new schema, lease-record; one field at development stability, allow.tool_args; everything else stable.

Added

Changed

1.1.0 — 2026-10-05

The first release after the review of 4 October 2026 (CDF spec contract-fix-batch-one-4, DR-182). Five of the review's ten improvements, in the order the guard first so every tightening that follows is classified and allow-listed by name. Additive within 1.x by the contract's own rule, mechanically checked: against 1.0.2 the guard reports 46 allow-listed tightenings, each with the fixture or real-data count that proves no conformant writer ever produced what it now refuses, and every real journal in the reference deployment (33,557 audit records, 5,652 signals, 4,535 provenance lines) validates with zero rejections. No existing hash or signature changes.

Added

Changed

Fixed

1.0.2 — 2026-09-19

Fixed

Changed

1.0.1 — 2026-09-19

The first release published from CI, and therefore the first carrying a provenance attestation — 1.0.0 went out by hand because npm trusted publishing must be configured on a package that already exists. A contract that asks other people to record what produced an artefact should be able to show what produced its own; from here it can.

No schema changed. This release is the specification, the vectors and the tooling around them. The published tarball is 91 files.

Added

Fixed

1.0.0 — 2026-09-19

First published release. Nine schemas, a conformance corpus of 20 valid and 26 invalid fixtures, and the additive-only lock.

Added

Notes on this release